CVE-2013-7303: XSS
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editerauteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7303?
CVE-2013-7303 has a medium severity rating due to its potential to allow remote attackers to inject malicious scripts.
How do I fix CVE-2013-7303?
To fix CVE-2013-7303, upgrade to SPIP version 2.1.25 or 3.0.13 or later.
What specific files are affected in CVE-2013-7303?
The affected files in CVE-2013-7303 are squelettes-dist/formulaires/inscription.php and prive/forms/editer_auteur.php.
Can CVE-2013-7303 be exploited remotely?
Yes, CVE-2013-7303 can be exploited remotely by injecting arbitrary web scripts via the author name field.
Which versions of SPIP are impacted by CVE-2013-7303?
SPIP versions prior to 2.1.25 and 3.0.x before 3.0.13 are impacted by CVE-2013-7303.