Description
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
References (8)
Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/83647
Exploit, Patch x_refsource_confirm
https://github.com/johndyer/mediaelement/commit/9223dc6bfc50251a9a3cba0210e71be80fc38ecd
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=955307
Mailing List mailing-list
x_refsource_mlist
http://seclists.org/oss-sec/2013/q2/111
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/53079
Patch, Vendor Advisory x_refsource_confirm
http://owncloud.org/about/security/advisories/oC-SA-2013-017
Patch mailing-list
x_refsource_mlist
http://seclists.org/oss-sec/2013/q2/133
Various Sources x_refsource_confirm
https://github.com/johndyer/mediaelement/tree/2.11.1
Scores
EPSS
0.0057
EPSS Percentile
68.6%
Details
CWE
CWE-79
Status
published
Products (50)
mediaelementjs/mediaelement.js
1.0.0
mediaelementjs/mediaelement.js
1.0.1
mediaelementjs/mediaelement.js
1.0.2
mediaelementjs/mediaelement.js
1.0.3
mediaelementjs/mediaelement.js
1.0.4
mediaelementjs/mediaelement.js
1.0.5
mediaelementjs/mediaelement.js
1.0.6
mediaelementjs/mediaelement.js
1.0.7
mediaelementjs/mediaelement.js
1.1.0
mediaelementjs/mediaelement.js
1.1.1
... and 40 more
Published
Feb 05, 2014
Tracked Since
Feb 18, 2026