Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/.
References
Configurations
Information
Published : 2014-07-02 11:55
Updated : 2015-08-28 09:34
NVD link : CVE-2014-4570
Mitre link : CVE-2014-4570
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
videowhisper
- video_presentation