CVE-2012-2399: XSS
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2399?
CVE-2012-2399 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2012-2399?
To fix CVE-2012-2399, upgrade your SWFupload implementation to a version later than 2.2.0.1, or update your WordPress to version 3.5.2 or later.
Which products are affected by CVE-2012-2399?
CVE-2012-2399 affects SWFupload versions 2.2.0.1 and earlier and multiple versions of WordPress prior to 3.5.2.
What type of vulnerability is CVE-2012-2399?
CVE-2012-2399 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web scripts or HTML.
Can CVE-2012-2399 be exploited remotely?
Yes, CVE-2012-2399 can be exploited remotely by attackers through tricking users into interacting with malicious content.