CVE-2013-4795: XSS
Published Apr 11, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7.12 allows remote attackers to inject arbitrary web script or HTML via a user full name.
Affected Software
29 affected components
ReviewBoard Review Board=1.6
ReviewBoard Review Board=1.6-beta1
ReviewBoard Review Board=1.6-beta2
ReviewBoard Review Board=1.6-rc1
ReviewBoard Review Board=1.6-rc2
ReviewBoard Review Board=1.6.1
ReviewBoard Review Board=1.6.2
ReviewBoard Review Board=1.6.3
ReviewBoard Review Board=1.6.10
ReviewBoard Review Board=1.6.11
ReviewBoard Review Board=1.6.12
ReviewBoard Review Board=1.6.13
ReviewBoard Review Board=1.6.14
ReviewBoard Review Board=1.6.15
ReviewBoard Review Board=1.6.16
ReviewBoard Review Board=1.6.17
ReviewBoard Review Board=1.7.0
ReviewBoard Review Board=1.7.0.1
ReviewBoard Review Board=1.7.1
ReviewBoard Review Board=1.7.2
ReviewBoard Review Board=1.7.3
ReviewBoard Review Board=1.7.4
ReviewBoard Review Board=1.7.5
ReviewBoard Review Board=1.7.6
ReviewBoard Review Board=1.7.7
ReviewBoard Review Board=1.7.8
ReviewBoard Review Board=1.7.9
ReviewBoard Review Board=1.7.10
ReviewBoard Review Board=1.7.11
Event History
Apr 11, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4795?
CVE-2013-4795 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2013-4795?
To fix CVE-2013-4795, update Review Board to version 1.6.18 or later, or 1.7.12 or later.
3
What versions of Review Board are affected by CVE-2013-4795?
CVE-2013-4795 affects Review Board versions 1.6.x before 1.6.18 and 1.7.x before 1.7.12.
4
What type of vulnerability is CVE-2013-4795?
CVE-2013-4795 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts.
5
Who can exploit CVE-2013-4795?
CVE-2013-4795 can be exploited by remote attackers who can manipulate user full names.