Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Zach Alexander

#51019de 53,635
4.3CVSS total
Vulnerabilidades · 1
PT-2014-2276
4.3
2014-04-25
Moxiecode Systems · Tinymce · CVE-2012-4230
**Name of the Vulnerable Software and Affected Versions** TinyMCE version 3.5.8 **Description** The issue concerns the bbcode plugin in TinyMCE, which fails to properly enforce the security policy. This specifically affects the encoding directive and the valid elements attribute, allowing for cross-site scripting (XSS) attacks. An example of exploitation involves using a textarea element. **Recommendations** For TinyMCE version 3.5.8, consider disabling the bbcode plugin until a patch is available to prevent potential XSS attacks. Restrict access to the valid elements attribute and encoding directive to minimize the risk of exploitation.