Junglewise Threat Intelligence

CVE-2013-2022: Happyworm jPlayer XSS in Flash SWF component

CVE-2013-2022 · Severity: info · CVSS 4.3 · Published 2022-05-17

Vendors: npm.

Executive brief

jPlayer is a popular open-source media library used to play audio and video on websites. A security flaw in its Flash-based component allows attackers to execute malicious scripts in a user's browser when they visit a site using an outdated version of the player. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

Multiple cross-site scripting (XSS) vulnerabilities exist in actionscript/Jplayer.as within the Flash SWF component (jplayer.swf) of jPlayer before version 2.3.0. The flaw is rooted in insufficient sanitization of the 'jQuery' and 'id' parameters. A remote attacker can exploit this by tricking a user into visiting a URL that passes malicious payloads into these parameters, leading to arbitrary script execution in the context of the victim's browser session. This specific issue (CVE-2013-2022) is distinct from other contemporary jPlayer XSS bugs as it bypasses previous blacklist-based fixes. The vulnerability is resolved in version 2.3.0.

Affected products

  • Happyworm jPlayer < 2.3.0

Timeline

  • 2013-04-29: advisory: CVE-2013-2022 assigned to this specific jPlayer XSS instance
  • 2013-08-17: disclosed: NVD publication date
  • 2013-04-20: patched: jPlayer 2.3.0 released with security fixes

References