Executive brief
video.js is a popular open-source video player library used across thousands of websites. A cross-site scripting (XSS) vulnerability in the track tag's src attribute allows attackers to inject and execute malicious code in the browsers of users viewing affected video players, potentially stealing session cookies, redirecting users to phishing sites, or defacing page content.
Technical details
The vulnerability is a cross-site scripting (CWE-79) flaw in video.js versions before 7.14.3 affecting the track tag's src attribute. The src attribute fails to properly escape HTML, allowing an attacker to bypass HTML escaping mechanisms and inject arbitrary JavaScript code. The attack requires no authentication and can be triggered over the network when a user visits a page with an embedded video.js player that loads a malicious track element. An attacker can achieve arbitrary JavaScript execution in the victim's browser context, leading to session hijacking, credential theft, or other client-side attacks. The vulnerability was fixed in version 7.14.3 by removing an IE8 URL parsing workaround that introduced the flaw.
Affected products
- video.js video.js before 7.14.3
Timeline
- 2021-07-28: disclosed: NVD published
- 2021-08-02: patched: Version 7.14.3 released with fix