CVE-2013-0234
Elgg < 1.7.16 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save.
Scores
EPSS
0.0054
EPSS Percentile
67.5%
Details
CWE
CWE-79
Status
published
Products (31)
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
... and 21 more
Published
Feb 02, 2014
Tracked Since
Feb 18, 2026