CVE-2013-3267: XSS
Published May 3, 2013
·Updated
Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
14 affected components
Joomla Joomla\!=2.5.0
Joomla Joomla\!=2.5.1
Joomla Joomla\!=2.5.2
Joomla Joomla\!=2.5.3
Joomla Joomla\!=2.5.4
Joomla Joomla\!=2.5.5
Joomla Joomla\!=2.5.6
Joomla Joomla\!=2.5.7
Joomla Joomla\!=2.5.8
Joomla Joomla\!=2.5.9
Joomla Joomla\!=3.0.0
Joomla Joomla\!=3.0.1
Joomla Joomla\!=3.0.2
Joomla Joomla\!=3.0.3
Event History
May 3, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3267?
CVE-2013-3267 is considered a medium severity vulnerability due to the potential for XSS attacks.
2
How do I fix CVE-2013-3267?
To fix CVE-2013-3267, you should update Joomla! to version 2.5.10 or 3.0.4 or later.
3
What versions of Joomla! are affected by CVE-2013-3267?
Joomla! versions 2.5.0 through 2.5.9 and 3.0.0 through 3.0.3 are affected by CVE-2013-3267.
4
What kind of attack can CVE-2013-3267 facilitate?
CVE-2013-3267 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
5
Are there any known exploits for CVE-2013-3267?
There are no specific public exploits documented for CVE-2013-3267, but the vulnerability provides an opportunity for XSS attacks.