CVE-2013-4759
Magnolia CMS - Multiple Cross-Site Scripting Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
6Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) fullname, or (3) email parameter to magnoliaPublic/demo-project/members-area/registration.html.
Múltiples vulnerabilidades de cross-site scripting (XSS) en el módulo Magnolia Form v1.x hasta v1.4.7 y v2.x anterior a v2.0.2 para Magnolia CMS, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) username, (2) fullname, o (3) email en magnoliaPublic/demo-project/members-area/registration.html.
Magnolia CMS versions 5.0.1, 5.0, 4.5.9, 4.5.8, and 4.5.7 suffer from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-07-04 CVE Reserved
- 2013-07-24 CVE Published
- 2013-07-24 First Exploit
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://osvdb.org/95628 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/85940 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/122527 | 2013-07-24 | |
https://www.exploit-db.com/exploits/38675 | 2013-07-24 | |
http://archives.neohapsis.com/archives/bugtraq/2013-07/0160.html | 2024-08-06 | |
http://packetstormsecurity.com/files/122527/Magnolia-CMS-5.0.1-Community-Edition-Cross-Site-Scripting.html | 2024-08-06 | |
http://www.securityfocus.com/bid/61423 | 2024-08-06 | |
https://www.htbridge.com/advisory/HTB23163 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 1.4 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "1.4" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 1.4.1 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "1.4.1" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 1.4.2 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "1.4.2" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 1.4.3 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "1.4.3" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 1.4.4 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "1.4.4" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 1.4.5 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "1.4.5" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 1.4.6 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "1.4.6" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 2.0 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "2.0" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|
Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Form Module Search vendor "Magnolia-cms" for product "Magnolia Form Module" | 2.0.1 Search vendor "Magnolia-cms" for product "Magnolia Form Module" and version "2.0.1" | - |
Affected
| in | Magnolia-cms Search vendor "Magnolia-cms" | Magnolia Cms Search vendor "Magnolia-cms" for product "Magnolia Cms" | - | community |
Safe
|