VulnerabilityModified
CVE-2013-4171
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.
MEDIUM 4.3EPSS 2.97%
Does this matter?
Lower severity and a low EPSS score (2.97%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.97% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/roller
- Source
- secalert@redhat.com
References
- http://rollerweblogger.org/project/entry/apache_roller_5_0_2Patch
- http://secunia.com/advisories/55862Vendor Advisory
- http://secunia.com/advisories/55877Vendor Advisory
- http://rollerweblogger.org/project/entry/apache_roller_5_0_2Patch
- http://secunia.com/advisories/55862Vendor Advisory
- http://secunia.com/advisories/55877Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.