CVE-2013-7351

Source
https://nvd.nist.gov/vuln/detail/CVE-2013-7351
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2013-7351.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2013-7351
Published
2020-01-02T20:15:15Z
Modified
2024-11-21T02:00:48Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.

References

Affected packages

Debian:12 / shaarli

Package

Name
shaarli
Purl
pkg:deb/debian/shaarli?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.41~beta~dfsg2-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / shaarli

Package

Name
shaarli
Purl
pkg:deb/debian/shaarli?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.41~beta~dfsg2-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}