CVE-2013-0194: XSS
Published Nov 20, 2019
·Updated
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.
Affected Software
2 affected componentsFixes available
Matomo Matomo<1.10.1
debian/matomo
5.3.1+dfsg-15.5.1+dfsg-3
Event History
Nov 20, 2019
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·03:05 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0194?
CVE-2013-0194 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2013-0194?
To fix CVE-2013-0194, upgrade to Piwik version 1.10.1 or later, which addresses this vulnerability.
3
What kind of attacks does CVE-2013-0194 enable?
CVE-2013-0194 enables remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
4
What versions of Piwik are affected by CVE-2013-0194?
CVE-2013-0194 affects all Piwik versions prior to 1.10.1.
5
Is CVE-2013-0194 related to other vulnerabilities?
Yes, CVE-2013-0194 is a different vulnerability compared to CVE-2013-0193 and CVE-2013-0195.