Impact
Paella Player is a set of libraries that build a multi‑stream video player. Until version 2.12.11 the library does not sanitize closed‑caption cue text, allowing an attacker to store malicious JavaScript in that text. When a user views a video with such captions, the script is rendered in the browser, enabling arbitrary code execution in the user’s browser context. This stored XSS flaw corresponds to CWE‑79 and is fixed in version 2.12.11.
Affected Systems
The vulnerability is present in the Paella Player library versions lower than 2.12.11, which are used in Opencast prior to version 19.7 and prior to 20.2. Therefore any installation of Opencast 19.6 or earlier, 20.1 or earlier, or any system that directly incorporates a Paella Player version older than 2.12.11 is affected. The marked releases (19.7 and 20.2) include the fix.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact. The EPSS score of < 1 % suggests that, as of the latest data, the likelihood of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely web‑based: an attacker who can insert or modify caption cue text will cause the malicious script to be stored and executed for any viewer of that video. With the available information, the critical risk is confined to victims who view the compromised captions, but any successful exploitation can compromise both confidentiality and integrity of the user session.
OpenCVE Enrichment
Github GHSA