CVE-2013-3728

kasseler-cms < 2 - Authenticated Cross-Site Scripting via cat Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-3728.

AI-analyzed exploit summary The provided code contains functional exploit examples for SQL injection (CVE-2013-3727), stored XSS (CVE-2013-3728), and CSRF (CVE-2013-3729) in Kasseler CMS. It includes detailed PoC code for each vulnerability, demonstrating how an attacker can exploit them.

Description

Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or HTML via the cat parameter in an admin_new_category action to admin.php.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/26623

The provided code contains functional exploit examples for SQL injection (CVE-2013-3727), stored XSS (CVE-2013-3728), and CSRF (CVE-2013-3729) in Kasseler CMS. It includes detailed PoC code for each vulnerability, demonstrating how an attacker can exploit them.

Classification
Working Poc 100%
Attack Type
Sqli | Xss | Csrf
Complexity
Moderate
Reliability
Reliable
Target: Kasseler CMS 2 r1223 and prior
Auth required
Prerequisites: Authenticated admin session for SQLi/CSRF · Ability to create categories for XSS
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (7)

Core 7
Core References
Various Sources x_refsource_confirm
http://diff.kasseler-cms.net/svn.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85408
Exploit mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2013/Jul/26
Patch, Vendor Advisory x_refsource_confirm
http://diff.kasseler-cms.net/svn/patches/1232.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/94780

Scores

EPSS 0.0295
EPSS Percentile 85.4%

Details

CWE
CWE-79
Status published
Products (1)
kasseler-cms/kasseler-cms < 2
Published Mar 13, 2014
Tracked Since Feb 18, 2026