CVE-2013-7351
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile…
Does this matter?
Lower severity and a low EPSS score (2.21%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- shaarli project/shaarli
- Source
- security@debian.org
References
- http://seclists.org/oss-sec/2014/q2/1Exploit, Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2014/q2/4Exploit, Mailing List, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92215Third Party Advisory, VDB Entry
- https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925aPatch, Third Party Advisory
- https://github.com/sebsauvage/Shaarli/issues/134Exploit, Third Party Advisory
- http://seclists.org/oss-sec/2014/q2/1Exploit, Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2014/q2/4Exploit, Mailing List, Patch, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92215Third Party Advisory, VDB Entry
- https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925aPatch, Third Party Advisory
- https://github.com/sebsauvage/Shaarli/issues/134Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.