Description
Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Email Template Designer-WP HTML Mail Cross-Site Scripting (3.0.9)
Oracle Database Server CVE-2009-2000 Vulnerability (CVE-2009-2000)
MySQL CVE-2019-2778 Vulnerability (CVE-2019-2778)
MediaWiki Other Vulnerability (CVE-2005-0536)
WordPress Plugin Simple File List Arbitrary File Upload (4.2.2)