ZeroHour

CVE-2021-23414

PoC ×3
CVSS 3.1
6.1 medium
EPSS
3%p84
Published
()
Modified
Description

This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.

Vendors
videojsfedoraproject
Products
video.js, fedora
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news