CVE-2013-7062: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote attackers to inject arbitrary web script or HTML via unspecified input in the (1) browseridmanager or (2) OFS.Image method.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-7062?
CVE-2013-7062 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML via unspecified input in Zope as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2.
How severe is CVE-2013-7062?
CVE-2013-7062 has a severity rating of 6.1 (medium).
What is the affected software for CVE-2013-7062?
The affected software for CVE-2013-7062 includes Plone versions 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2.
How do I fix CVE-2013-7062?
To fix CVE-2013-7062, it is recommended to upgrade to Plone version 4.3.2, 4.1.6, 4.0.9, or 3.3.6 depending on the affected version.
What is the CWE ID for CVE-2013-7062?
The CWE ID for CVE-2013-7062 is 79.