PT-2026-95108 · Opencast+1 · Opencast+1
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Paella Player versions prior to 2.12.11
Opencast versions prior to 19.7
Opencast versions prior to 20.2
Description
An issue exists where the player renders caption cue text into
innerHTML without proper escaping. This allows a user with content authoring permissions to upload a subtitle file (such as WebVTT or DFXP) containing malicious HTML or JavaScript. When a viewer enables captions for the affected event, the script executes within the Opencast origin in the viewer's browser session. This affects anonymous viewers as well as authenticated staff, potentially leading to session theft, CSRF-token theft, and unauthorized actions against the Opencast REST API.The issue is triggered when the player processes caption tracks served via the
/search/episode.json endpoint. The vulnerable behavior occurs because the caption plugins, enabled by default, append the cue text directly to the captionsContainer.innerHTML sink without sanitization.Recommendations
Update Paella Player to version 2.12.11 or later.
Update Opencast to version 19.7 or later.
Update Opencast to version 20.2 or later.
As a temporary mitigation, disable the WebVTT and DFXP caption plugins in the player configuration.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencast
Paella-Player