CVE-2013-1942 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 5.5% (pctl 93)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.20, as used in ownCloud Server before 5.0.4 and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, as demonstrated using document.write in the jQuery parameter, a different vulnerability than CVE-2013-2022 and CVE-2013-2023.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 5.49% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-08-15 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| happyworm | jplayer |
| owncloud | owncloud |
| owncloud | owncloud server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | jPlayer - 'Jplayer.swf' Script Cross-Site Scripting | 2013-03-29 |
References
- http://marc.info/?l=oss-security&m=136570964825921&w=2
- http://marc.info/?l=oss-security&m=136726705917858&w=2
- http://marc.info/?l=oss-security&m=136773622321563&w=2
- http://owncloud.org/about/security/advisories/oC-SA-2013-014/
- http://seclists.org/fulldisclosure/2013/Apr/192
- http://www.jplayer.org/2.3.0/release-notes/
- http://www.securityfocus.com/bid/59030
- https://github.com/happyworm/jPlayer/commit/e8ca190f7f972a6a421cb95f09e138720e40ed6d
- http://marc.info/?l=oss-security&m=136570964825921&w=2
- http://marc.info/?l=oss-security&m=136726705917858&w=2
- http://marc.info/?l=oss-security&m=136773622321563&w=2
- http://owncloud.org/about/security/advisories/oC-SA-2013-014/
- http://seclists.org/fulldisclosure/2013/Apr/192
- http://www.jplayer.org/2.3.0/release-notes/
- http://www.securityfocus.com/bid/59030
- https://github.com/happyworm/jPlayer/commit/e8ca190f7f972a6a421cb95f09e138720e40ed6d
→ the Explorer · watch your stack · NVD