CVE-2013-1938: XSS
Published Feb 12, 2020
·Updated
Zimbra 2013 has XSS in aspell.php
Affected Software
1 affected component
Zimbra Zimbra=2013
Remediation
Patch Available
Patch Available
Event History
Feb 12, 2020
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-1938?
The severity of CVE-2013-1938 is medium with a CVSS score of 6.1.
2
How does CVE-2013-1938 affect Zimbra 2013?
CVE-2013-1938 affects Zimbra 2013 by introducing a cross-site scripting vulnerability in aspell.php.
3
How can I fix CVE-2013-1938 in Zimbra 2013?
To fix CVE-2013-1938 in Zimbra 2013, you should patch or upgrade Zimbra Collaboration (ZCS) to a version that addresses the vulnerability.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2013-1938?
The Common Weakness Enumeration (CWE) ID for CVE-2013-1938 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
5
Where can I find more information about CVE-2013-1938?
You can find more information about CVE-2013-1938 on the following websites: [1] http://www.openwall.com/lists/oss-security/2013/04/09/14 [2] http://www.openwall.com/lists/oss-security/2013/04/09/15 [3] http://www.securityfocus.com/bid/58913