Sploitus

CVE-2012-4230

1 known exploit for CVE-2012-4230

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

Affected products
Tinymce
Tinymce
= 3.5.8
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
1.2% (65th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2014-04-25
CVE-2012-4230 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2012-4230

Proof-of-concept code and exploit modules indexed by Sploitus