6.1
CVE-2014-4567
- EPSS 1.19%
- Veröffentlicht 27.12.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 02:10:27
- Erkennungen
HTML5 Webcam Microphone Recorder Forms < 1.55 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in comments/videowhisper2/r_logout.php in the Video Comments Webcam Recorder plugin 1.55, as downloaded before 20140116 for WordPress allows remote attackers to inject arbitrary web script or HTML via the message parameter.
Mögliche Gegenmaßnahme
Webcam/Screen/Mic Recorder for Video Comments and Forms: Update to version 1.55.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Videowhisper ≫ Video Comments Webcam Recorder SwPlatform wordpress Version <= 1.55
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Webcam/Screen/Mic Recorder for Video Comments and Forms
Version
*-1.55
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.19% | 0.64 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://codevigilant.com/disclosure/wp-plugin-video-comments-webcam-recorder-a3-cross-site-scripting-xss
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=839986%40video-comments-webcam-recorder&old=686438%40video-comments-webcam-recorder
https://www.wordfence.com/threat-intel/vulnerabilities/id/1ddb9fc8-bed4-42ff-9664-6ea8fb136ec0