Описание
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
wordpress | fixed | 4.9.2+dfsg-1 | package | |
wordpress | not-affected | stretch | package | |
wordpress | not-affected | jessie | package | |
wordpress | not-affected | wheezy | package |
Примечания
For jessie and stretch version the files silverlightmediaelement.xap and
flashmediaelement.swf have been removed with the 4.1+dfsg-1 version.
sid in version 4.9.1+dfsg-1 did as well *not* have the files but track here the
final wordpress version 4.9.2 which finally removed the mediaelement files.
https://wordpress.org/news/2018/01/wordpress-4-9-2-security-and-maintenance-release/
https://github.com/WordPress/WordPress/commit/3fe9cb61ee71fcfadb5e002399296fcc1198d850
EPSS
Связанные уязвимости
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
EPSS