XSS vulnerability in MediaElement.js (oC-SA-2013-017)


Issued on:

18.04.2013

CVE:
  • CVE-2013-1967 (MediaElement.js)
Affected Software:
  • ownCloud Server < 5.0.5
  • ownCloud Server < 4.5.10
Risk:

Medium

Commits: Description

A cross-site scripting (XSS) vulnerability in all ownCloud versions prior to 5.0.5 including the 4.5.x branch allows remote attackers to execute arbitrary javascript when a user opens a special crafted URL.

This vulnerability exists in the bundled 3rdparty plugin “MediaElement.js”, “MediaElement.js” released version 2.11.2 which addresses the problem.

Credits

The ownCloud Team would like to thank Malte Batram for discovering this vulnerability and responsibly disclosing this to us and upstream.