SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-4230

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific…

MEDIUM 4.3EPSS 1.20%

Does this matter?

Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.

Description

The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors, as demonstrated using a textarea element.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.20% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
tinymce/tinymce
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.