Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by insufficient input neutralization in the Winlin Live Streaming Video Player – by SRS Player plugin. An attacker can inject and execute arbitrary JavaScript when a victim loads a page that includes the vulnerable plugin. This can lead to theft of credentials, session hijacking, or defacement, affecting the confidentiality, integrity, and availability of the site from the perspective of end users. The weakness is an example of CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
Winlin Live Streaming Video Player – by SRS Player, version 1.0.18 and earlier. No specific sub‑release information is provided; all releases up to and including 1.0.18 are vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the near term, and the vulnerability is not present in CISA’s KEV catalog. The likely attack vector is a maliciously crafted input that the plugin does not properly escape; any user who views the affected page can be targeted. Exploitation would require the user to visit a page containing the vulnerable plugin, after which arbitrary JavaScript could run in the victim’s browser context.
OpenCVE Enrichment
EUVD