WordPress 插件是WordPress开源的一个应用插件。 WordPress 插件 FV Flowplayer 视频播放器存在跨站脚本漏洞,该漏洞源于~/view/stats.php 文件中的 player_id 参数容易受到反射跨站点脚本攻击,该参数允许攻击者在 7.5.0.727 - 7.5.2.727 版本中注入任意 Web 脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FV Flowplayer Video Player | FV Flowplayer Video Player | 7.5.0.727 - 7.5.2.727 7.5.2.727 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts in versions 7.5.0.727 - 7.5.2.727. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-39350.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet