CVE-2014-1906: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lbstatus.php; (2) msg parameter to vcchatlog.php; n parameter to (3) channel.php, (4) htmlchat.php, (5) video.php, or (6) videotext.php; (7) message parameter to lblogout.php; or ct parameter to (8) lbstatus.php or (9) vstatus.php in ls/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1906?
CVE-2014-1906 is considered a Medium severity vulnerability due to its ability to allow remote attackers to inject arbitrary web scripts.
How do I fix CVE-2014-1906?
To fix CVE-2014-1906, update the VideoWhisper Live Streaming Integration plugin to version 4.29.5 or later.
What kind of vulnerabilities are present in CVE-2014-1906?
CVE-2014-1906 contains multiple cross-site scripting (XSS) vulnerabilities.
Which versions of VideoWhisper Live Streaming Integration are affected by CVE-2014-1906?
Versions of VideoWhisper Live Streaming Integration prior to 4.29.5, including those from 1.0.2 to 4.27.3, are affected by CVE-2014-1906.
Can CVE-2014-1906 affect user data?
Yes, CVE-2014-1906 can potentially compromise user data integrity due to the ability of attackers to inject scripts.