WordPress Core < 4.9.1 - Cross-domain Flash injection

2017-10-10 00:00
Anonymous

Strategic Overview

Status
Patched in 3.7.25
Affected CoreWordPress 4.9
Affected Version3.7 – 4.9.1 · 14 branches
CVSS4.7Medium
CVECVE-2016-9263
View all WordPress 4.9 vulnerabilities

Vulnerability Overview

WordPress through 4.9.1, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.25, 3.8.25, 3.9.24, 4.0.22, 4.1.22, 4.2.19, 4.3.15, 4.4.14, 4.5.13, 4.6.10, 4.7.9, 4.8.5, 4.9.2 --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C