CVE-2012-2399

Source
https://cve.org/CVERecord?id=CVE-2012-2399
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2012-2399.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2012-2399
Downstream
Withdrawn
2026-01-27T04:11:12.821846Z
Published
2012-04-21T23:55:01Z
Modified
2026-01-27T04:11:12.821846Z
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.

References

Affected packages