CVE-2013-0234

Elgg < 1.7.17 and 1.8.x < 1.8.13 - Cross-Site Scripting via Twitter Widget params[twitter_username] Parameter

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save.

References (8)

Core 8
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jan/251
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/01/29/4
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/52007
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/57569

Scores

EPSS 0.0146
EPSS Percentile 70.1%

Details

CWE
CWE-79
Status published
Products (30)
elgg/elgg 1.8.0.1
elgg/elgg 1.8.1
elgg/elgg 1.8.3
elgg/elgg 1.8.4
elgg/elgg 1.8.5
elgg/elgg 1.8.6
elgg/elgg 1.8.7
elgg/elgg 1.8.8
elgg/elgg 1.8.9
elgg/elgg 1.8.10
... and 20 more
Published Feb 02, 2014
Tracked Since Feb 18, 2026