CVE-2013-0730
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to…
Does this matter?
Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.php or (2) user parameter to application/modules/admin/controllers/UserController.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sourcefabric/newscoop
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://forum.sourcefabric.org/discussion/15052/security-patch-released-for-newscoop-4-1Patch
- http://secunia.com/advisories/51921Vendor Advisory
- https://github.com/sourcefabric/Newscoop/commit/4f948ba3afaaeb616006cbabc85906ef3254169d
- http://forum.sourcefabric.org/discussion/15052/security-patch-released-for-newscoop-4-1Patch
- http://secunia.com/advisories/51921Vendor Advisory
- https://github.com/sourcefabric/Newscoop/commit/4f948ba3afaaeb616006cbabc85906ef3254169d
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.