XSS Vulnerability in MediaElement.js
Platform: ownCloud Server
Versions: 4.5.10, 5.0.5,
Risk level: High
This vulnerability exists in the bundled 3rdparty plugin “MediaElement.js”, “MediaElement.js” released version 2.11.2 which addresses the problem.
- ownCloud Server < 5.0.5 (CVE-2013-1967)
- ownCloud Server < 4.5.10 (CVE-2013-1967)
It is recommended that all instances are upgraded to ownCloud Server 5.0.5 or 4.5.10.
The ownCloud team thanks the following people for their research and responsible disclosure of the above advisory:
- Malte Batram – Vulnerability discovery and disclosure.