Security Advisory

CVE-2012-4230

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-04-25 10:00:00
Last updated 2024-08-06 20:28:07
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.