Vulnerabilities/

MediaElement Vulnerable to Reflected XSS

Severity:
Medium

Description

Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.swf in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by “jsinitfunctio%gn.

Recommendation

Update the mediaelement package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mediaelement
Anything's wrong? Let us know Last updated on April 25, 2024

This issue is available in SmartScanner Professional

See Pricing