CVE-2016-4567Cross-site Scripting in Mediaelement

CWE-79Cross-site Scripting10 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
4.2%
top 11.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Packagistcontao-components/mediaelement2.14.22.21.1
Packagistcontao/core3.0.03.5.15

Patches

🔴Vulnerability Details

4
GHSA
MediaElement Vulnerable to Reflected XSS2022-05-17
OSV
MediaElement Vulnerable to Reflected XSS2022-05-17
OSV
CVE-2016-4567: Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement2016-05-22
CVEList
CVE-2016-4567: Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement2016-05-22

📋Vendor Advisories

1
Debian
CVE-2016-4567: mediaelement - Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaE...2016

💬Community

4
Bugzilla
flashmediaelement.swf XSS in qsurvey.mozilla.com2016-07-07
Bugzilla
CVE-2016-4566 CVE-2016-4567 wordpress: 4.5.2 Security Release2016-05-09
Bugzilla
CVE-2016-4566 CVE-2016-4567 wordpress: 4.5.2 Security Release [epel-all]2016-05-09
Bugzilla
CVE-2016-4566 CVE-2016-4567 wordpress: 4.5.2 Security Release [fedora-all]2016-05-09
CVE-2016-4567 — Cross-site Scripting in Mediaelement | cvebase