Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-4230

Опубликовано: 25 апр. 2014
Источник: debian
EPSS Низкий

Описание

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tinymceremovedpackage
tinymceno-dsabusterpackage
tinymceno-dsastretchpackage
tinymceno-dsajessiepackage
tinymceno-dsasqueezepackage
tinymceno-dsawheezypackage

EPSS

Процентиль: 69%
0.00621
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

nvd
почти 12 лет назад

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

github
больше 3 лет назад

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

EPSS

Процентиль: 69%
0.00621
Низкий