Impact
Improper neutralization of input during web page generation allows an attacker to inject malicious scripts that are reflected back to the victim when they visit a crafted URL. This type of Cross‑Site Scripting (CWE‑79) can lead to defacement, credential theft, or arbitrary script execution within the context of the site. The vulnerability does not require authentication, so any guest or logged‑in user can be affected if they click a malicious link.
Affected Systems
LambertGroup’s Revolution Video Player With Bottom Playlist plugin is affected, specifically all versions from the earliest not specified up to and including 2.9.2.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity; the attack complexity is not specified in the CVE data. The EPSS score of less than 1% suggests low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by embedding malicious JavaScript in user‑controlled parameters or links; affected visitors will then execute the script when rendering the page, potentially compromising their session or the site content.
OpenCVE Enrichment
EUVD