CVE-2013-4888

Digital Signage Xibo 1.4.2 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jacob Holcomb · textwebappsphp
https://www.exploit-db.com/exploits/38745

Scores

EPSS 0.0039
EPSS Percentile 59.5%

Details

CWE
CWE-79
Status published
Products (2)
xibosignage/xibo
n/a/n/a
Published Jan 29, 2014
Tracked Since Feb 18, 2026