CVE-2016-4567
MEDIUMMediaelementjs Mediaelement.js < 2.20.1 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
References (9)
Scores
CVSS v3
6.1
EPSS
0.0415
EPSS Percentile
88.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (5)
mediaelementjs/mediaelement.js
< 2.20.1
wordpress/wordpress
< 4.5.1
npm/mediaelement
< 2.11.1npm
contao-components/mediaelement
< 2.21.1Packagist
contao/core
< 3.5.15Packagist
Timeline
Published
May 22, 2016
Tracked Since
Feb 18, 2026