MEDIUM6.1
GHSA-277w-qpxr-2549
MediaElement Vulnerable to Reflected XSS
Quick fix
GHSA-277w-qpxr-2549 — mediaelement: upgrade to the fixed version with the command below.
npm install mediaelement@2.11.1Details
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.swf in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/contao-components/mediaelement
Introduced in:
2.14.2Fixed in: 2.21.1Fix
composer require contao-components/mediaelement:^2.21.1References
- https://nvd.nist.gov/vuln/detail/CVE-2016-4567[ADVISORY]
- https://github.com/johndyer/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e[WEB]
- https://github.com/mediaelement/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e[WEB]
- https://codex.wordpress.org/Version_4.5.2[WEB]
- https://contao.org/en/news/contao-3_5_15.html[WEB]
- https://core.trac.wordpress.org/changeset/37371[WEB]
- https://gist.github.com/cure53/df34ea68c26441f3ae98f821ba1feb9c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao-components/mediaelement/CVE-2016-4567.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2016-4567.yaml[WEB]
- https://github.com/johndyer/mediaelement/blob/master/changelog.md[WEB]
- https://github.com/mediaelement/mediaelement/blob/b992ccf5f0c04a207d98bbb0868420751a61ec90/changelog.md?plain=1#L1024[WEB]
- https://github.com/mediaelement/mediaelement/blob/master/changelog.md[WEB]
- https://web.archive.org/web/20170205142412/http://www.securitytracker.com/id/1035818[WEB]
- https://wordpress.org/news/2016/05/wordpress-4-5-2[WEB]
- https://wpvulndb.com/vulnerabilities/8488[WEB]
- http://www.openwall.com/lists/oss-security/2016/05/07/2[WEB]
- http://www.securitytracker.com/id/1035818[WEB]