CVE-2016-4567
22.05.2016, 01:59
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
Vendor | Product | Version |
---|---|---|
mediaelementjs | mediaelement.js | 𝑥 ≤ 2.20.1 |
wordpress | wordpress | 𝑥 ≤ 4.5.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References