CVE-2014-4535
import_legacy_media_project import_legacy_media Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2014-4535 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
import_legacy_mediaBrowse import_legacy_media_project / import_legacy_media | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMImport Legacy Media <= 0.1 - Cross-Site ScriptingCVSS 6.1
A cross-site scripting vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
Impact
Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.
Remediation
Update to the latest version of the Import Legacy Media plugin (0.1 or higher) to mitigate this vulnerability.
Source: ProjectDiscovery