CVE-2013-4889: XSS
Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new administrator via the AddUser action or (2) conduct cross-site scripting (XSS) attacks, as demonstrated by CVE-2013-4888.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4889?
CVE-2013-4889 has a medium severity rating due to its potential to allow remote attackers to hijack administrator authentication.
How do I fix CVE-2013-4889?
To fix CVE-2013-4889, upgrade to a patched version of Xibo that addresses the CSRF vulnerabilities.
What types of attacks can be performed using CVE-2013-4889?
CVE-2013-4889 can be exploited for cross-site request forgery (CSRF) and cross-site scripting (XSS) attacks.
Which version of Xibo is vulnerable to CVE-2013-4889?
Xibo version 1.4.2 is the specific version affected by CVE-2013-4889.
What components are primarily affected by CVE-2013-4889?
CVE-2013-4889 primarily affects the index.php component of the Digital Signage Xibo application.