CVE-2013-1636: XSS
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (comjnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1636?
CVE-2013-1636 has a medium severity rating due to its cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-1636?
To fix CVE-2013-1636, update the affected software to Pretty Link Lite version 1.6.3 or higher, JNews 8.0.2 or higher, or CiviCRM version 4.3.4 or higher.
What software is affected by CVE-2013-1636?
CVE-2013-1636 affects Pretty Link Lite versions prior to 1.6.3, JNews version 8.0.1, and CiviCRM versions 3.1.0 through 4.3.3.
Is CVE-2013-1636 exploitable remotely?
Yes, CVE-2013-1636 is exploitable remotely, potentially allowing attackers to conduct cross-site scripting attacks on users.
What actions should I take if I am using software affected by CVE-2013-1636?
If using affected software for CVE-2013-1636, immediately update to the latest versions to mitigate the vulnerability.