VideoJS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-23414 - Vulnerability Database
VideoJS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-23414
Medium
Reference:
CVE-2021-23414
Title:
VideoJS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.