CVE-2012-4230
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.
- Affected products
- Tinymce
- Tinymce
- = 3.5.8
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.2% (65th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2014-04-25
CVE-2012-4230 at NVD
1 known exploit for CVE-2012-4230
Proof-of-concept code and exploit modules indexed by Sploitus