CVE-2014-4569
01.07.2014, 14:55
Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.
Vendor | Product | Version |
---|---|---|
videowhisper | videowhisper_live_streaming_integration | 𝑥 ≤ 4.27 |
videowhisper | videowhisper_live_streaming_integration | 1.0.2 |
videowhisper | videowhisper_live_streaming_integration | 2.0 |
videowhisper | videowhisper_live_streaming_integration | 2.1 |
videowhisper | videowhisper_live_streaming_integration | 2.2 |
videowhisper | videowhisper_live_streaming_integration | 4.05 |
videowhisper | videowhisper_live_streaming_integration | 4.07 |
videowhisper | videowhisper_live_streaming_integration | 4.25 |
videowhisper | videowhisper_live_streaming_integration | 4.27.2 |
𝑥
= Vulnerable software versions
References