Vulnerability Details CVE-2023-49178
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Hdwplayer HDW Player Plugin (Video Player & Video Gallery) allows Reflected XSS.This issue affects HDW Player Plugin (Video Player & Video Gallery): from n/a through 5.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.7%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2023-49178
-
cpe:2.3:a:hdwplayer:hdw_player:1.0
-
cpe:2.3:a:hdwplayer:hdw_player:2.0
-
cpe:2.3:a:hdwplayer:hdw_player:2.1
-
cpe:2.3:a:hdwplayer:hdw_player:2.4
-
cpe:2.3:a:hdwplayer:hdw_player:2.4.3
-
cpe:2.3:a:hdwplayer:hdw_player:3.1
-
cpe:2.3:a:hdwplayer:hdw_player:3.2
-
cpe:2.3:a:hdwplayer:hdw_player:3.3
-
cpe:2.3:a:hdwplayer:hdw_player:3.4
-
cpe:2.3:a:hdwplayer:hdw_player:4.0
-
cpe:2.3:a:hdwplayer:hdw_player:4.3
-
cpe:2.3:a:hdwplayer:hdw_player:4.4
-
cpe:2.3:a:hdwplayer:hdw_player:5.0