VDB
Sign up
MEDIUM6.1

GHSA-277w-qpxr-2549

MediaElement Vulnerable to Reflected XSS

Quick fix

GHSA-277w-qpxr-2549 — mediaelement: upgrade to the fixed version with the command below.

npm install mediaelement@2.11.1

Details

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.swf in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mediaelement
Introduced in: 0Fixed in: 2.11.1
Fixnpm install mediaelement@2.11.1
Packagist/contao-components/mediaelement
Introduced in: 2.14.2Fixed in: 2.21.1
Fixcomposer require contao-components/mediaelement:^2.21.1
Packagist/contao/core
Introduced in: 3.0.0Fixed in: 3.5.15
Fixcomposer require contao/core:^3.5.15

References