CVE-2013-4556

SPIP <3.0.12, <2.1.24 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.

Scores

EPSS 0.0033
EPSS Percentile 55.6%

Details

CWE
CWE-79
Status published
Products (50)
spip/spip < 2.1.23
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
spip/spip
... and 40 more
Published Nov 18, 2013
Tracked Since Feb 18, 2026