-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ezsystems/demobundle | composer | >= 5.4.0, < 5.4.6.1 | 5.4.6.1 |
The advisory explicitly states the vulnerability stems from an outdated VideoJS Flash-based player (video-js.swf file) but provides no specific function-level details. The resolution was file removal rather than patching specific functions. Without access to: 1) The exact vulnerable VideoJS version's source code, 2) Commit diffs showing vulnerable code patterns, or 3) XSS payload reproduction details, we cannot confidently identify specific vulnerable functions. The vulnerability appears to reside in the Flash player's handling of external inputs, but Flash/AS3 reverse-engineering would be required to pinpoint exact functions - information not provided in the advisory.