CVE-2013-4556
EPSS 0.33%
Description
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.
How to fix CVE-2013-4556
To remediate CVE-2013-4556, upgrade the affected package to a fixed version below.
- Debian/spip—upgrade to 2.1.24-1 or later
Is CVE-2013-4556 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1.24-1