CVE-2013-6837

No-margin-for-errors Prettyphoto < 3.1.4 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

Scores

EPSS 0.0060
EPSS Percentile 69.1%

Details

CWE
CWE-79
Status published
Products (2)
no-margin-for-errors/prettyphoto < 3.1.4
n/a/n/a
Published Dec 19, 2013
Tracked Since Feb 18, 2026