CVE-2013-4888: XSS
Published Jan 29, 2014
·Updated
Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page.
Affected Software
2 affected components
Springsignage Xibo=1.4.2
Xibosignage Xibo=1.4.2
Event History
Jan 29, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-4888?
CVE-2013-4888 is classified as a medium severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2013-4888?
To fix CVE-2013-4888, upgrade your Xibo installation to version 1.4.3 or later.
3
What type of vulnerability is CVE-2013-4888?
CVE-2013-4888 is a cross-site scripting (XSS) vulnerability.
4
What software is affected by CVE-2013-4888?
CVE-2013-4888 affects Digital Signage Xibo version 1.4.2.
5
What can attackers achieve with CVE-2013-4888?
Attackers can inject arbitrary web scripts or HTML into the application, compromising user sessions or injecting malicious content.