CVE-2013-7303
Publication date 30 January 2014
Last updated 24 July 2024
Ubuntu priority
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field.
Status
Package | Ubuntu Release | Status |
---|---|---|
spip | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
seth-arnold
Might be 'low' or 'negligible' if the author is the one to inject the XSS and if the author is generally allowed arbitrary HTML input somewhere else.