CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
Percentile
61.4%
The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE
security policy for the (1) encoding directive and (2) valid_elements
attribute, which allows attackers to conduct cross-site scripting (XSS)
attacks via application-specific vectors, as demonstrated using a textarea
element.
osvdb.org/91130
packetstormsecurity.com/files/120750/TinyMCE-3.5.8-Cross-Site-Scripting.html
seclists.org/fulldisclosure/2013/Mar/114
www.madirish.net/554
xforce.iss.net/xforce/xfdb/82744
launchpad.net/bugs/cve/CVE-2012-4230
nvd.nist.gov/vuln/detail/CVE-2012-4230
security-tracker.debian.org/tracker/CVE-2012-4230
www.cve.org/CVERecord?id=CVE-2012-4230