Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-4230

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-4230
Last Modified 25 Apr 2014 01:19:18
Published 25 Apr 2014 10:15:30
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-4230

Summary

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

Vulnerable Systems

Application

  • Tinymce 3.5.8


References

XF - tinymce-htmlentities-xss(82744)

BID - 58424

MISC - http://www.madirish.net/554

FULLDISC - 20130311 XSS Vulnerability in TinyMCE

MISC - http://packetstormsecurity.com/files/120750/TinyMCE-3.5.8-Cross-Site-Scripting.html

OSVDB - 91130


Last Updated: 27 May 2016 11:05:05