CVE-2013-4556: XSS
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editerauteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the urlsite parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4556?
CVE-2013-4556 is classified as a medium severity vulnerability due to its cross-site scripting (XSS) nature.
How do I fix CVE-2013-4556?
To fix CVE-2013-4556, you should upgrade your SPIP installation to version 3.0.12 or later, and 2.1.24 or later.
What versions of SPIP are affected by CVE-2013-4556?
CVE-2013-4556 affects SPIP versions prior to 2.1.24 and 3.0.x before 3.0.12.
What is the impact of CVE-2013-4556 on web security?
The impact of CVE-2013-4556 includes allowing remote attackers to inject arbitrary HTML or web scripts into the author page.
Is CVE-2013-4556 still a concern for modern SPIP installations?
CVE-2013-4556 is not a concern for modern SPIP installations if they have been updated to versions that address this vulnerability.