CVE-2013-0234

Elgg < 1.7.16 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save.

Scores

EPSS 0.0054
EPSS Percentile 67.5%

Details

CWE
CWE-79
Status published
Products (31)
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
... and 21 more
Published Feb 02, 2014
Tracked Since Feb 18, 2026