Vulnerabilities/

Cross-site Scripting in video.js

Severity:
Medium

Description

This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.

Recommendation

Update the video.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
video.js
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing