Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-94pj-jgcq-pjjg

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

EPSS

Процентиль: 78%
0.01241
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.7
ubuntu
почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
nvd
почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
debian
почти 8 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandb ...

EPSS

Процентиль: 78%
0.01241
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-20