CVE-2013-4759

Magnolia Form module <1.4.7-2.0.2 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) fullname, or (3) email parameter to magnoliaPublic/demo-project/members-area/registration.html.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge · htmlwebappsphp
https://www.exploit-db.com/exploits/38675

Scores

EPSS 0.1030
EPSS Percentile 93.2%

Details

CWE
CWE-79
Status published
Products (9)
magnolia-cms/magnolia_form_module 1.4
magnolia-cms/magnolia_form_module 1.4.1
magnolia-cms/magnolia_form_module 1.4.2
magnolia-cms/magnolia_form_module 1.4.3
magnolia-cms/magnolia_form_module 1.4.4
magnolia-cms/magnolia_form_module 1.4.5
magnolia-cms/magnolia_form_module 1.4.6
magnolia-cms/magnolia_form_module 2.0
magnolia-cms/magnolia_form_module 2.0.1
Published Aug 09, 2013
Tracked Since Feb 18, 2026