CVE-2014-4569: XSS
Published Jul 1, 2014
·Updated
Cross-site scripting (XSS) vulnerability in ls/vvlogin.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomname parameter.
Affected Software
9 affected components
VideoWhisper Videowhisper Live Streaming Integration Wordpress<=4.27
VideoWhisper Videowhisper Live Streaming Integration Wordpress=1.0.2
VideoWhisper Videowhisper Live Streaming Integration Wordpress=2.0
VideoWhisper Videowhisper Live Streaming Integration Wordpress=2.1
VideoWhisper Videowhisper Live Streaming Integration Wordpress=2.2
VideoWhisper Videowhisper Live Streaming Integration Wordpress=4.05
VideoWhisper Videowhisper Live Streaming Integration Wordpress=4.07
VideoWhisper Videowhisper Live Streaming Integration Wordpress=4.25
VideoWhisper Videowhisper Live Streaming Integration Wordpress=4.27.2
Remediation
Event History
Jul 1, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4569?
The severity of CVE-2014-4569 is classified as medium due to its ability to allow attackers to inject arbitrary web scripts or HTML.
2
How do I fix CVE-2014-4569?
To fix CVE-2014-4569, update the VideoWhisper Live Streaming Integration plugin to version 4.27.3 or newer.
3
What versions are affected by CVE-2014-4569?
CVE-2014-4569 affects VideoWhisper Live Streaming Integration plugin versions 4.27.2 and earlier.
4
What type of vulnerability is CVE-2014-4569?
CVE-2014-4569 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2014-4569 be exploited remotely?
Yes, CVE-2014-4569 can be exploited remotely by attackers injecting scripts through the room_name parameter.