Security Advisory

CVE-2021-23414

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-07-28 07:20:11
Last updated 2024-09-16 23:46:55
Assigner snyk
State PUBLISHED

Description

This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.