CVE-2013-5583: XSS
Published Dec 29, 2013
·Updated
Cross-site scripting (XSS) vulnerability in libraries/idnaconvert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Affected Software
2 affected componentsFixes available
Joomla Joomla\!=3.1.5
composer/joomla/joomla-cms<=3.1.5
3.1.6
Event History
Dec 29, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
May 17, 2022
Advisory Published
via GitHub·03:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-5583?
The severity of CVE-2013-5583 is classified as medium due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2013-5583?
To fix CVE-2013-5583, upgrade your Joomla! installation to version 3.1.6 or newer.
3
What versions of Joomla! are affected by CVE-2013-5583?
Joomla! version 3.1.5 is specifically affected by CVE-2013-5583.
4
Can CVE-2013-5583 allow attackers to perform phishing attacks?
Yes, CVE-2013-5583 can be exploited by attackers to perform phishing attacks through injected scripts.
5
What parameters are involved in the CVE-2013-5583 vulnerability?
The lang parameter in libraries/idna_convert/example.php is involved in the CVE-2013-5583 vulnerability.