Description
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Import XML and RSS Feeds Arbitrary File Upload (2.1.5)
WordPress Plugin All In One Schema.org Rich Snippets Cross-Site Scripting (1.4.4)
WordPress Plugin Mimetic Books Cross-Site Scripting (0.2.13)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0735)