Releases8
Frequency2 months 5 days
Last Release
Stars283
Flowplayer Flash, the video player for the Web

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.