Description
This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Memphis Documents Library Arbitrary File Download (3.1.5)
WordPress Plugin Sell Downloads Unspecified Vulnerability (1.0.85)
WordPress Plugin Contact Form Widget-Contact Query, Form Maker SQL Injection (1.0.9)
Apache HTTP Server Integer Overflow or Wraparound Vulnerability (CVE-2022-22721)
Jenkins Incorrect Authorization Vulnerability (CVE-2020-2104)