CVE-2013-6168
Zikula Application Framework < 1.3.5 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the returnpage parameter to index.php.
References (5)
Scores
EPSS
0.0034
EPSS Percentile
56.4%
Details
CWE
CWE-79
Status
published
Products (7)
zikula/zikula_application_framework
< 1.3.5
zikula/zikula_application_framework
zikula/zikula_application_framework
zikula/zikula_application_framework
zikula/zikula_application_framework
zikula/zikula_application_framework
n/a/n/a
Published
Nov 14, 2013
Tracked Since
Feb 18, 2026