4.3
CVE-2013-0734
- EPSS 0.43%
- Veröffentlicht 28.03.2014 15:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Mingle Forum <= 1.0.33.3 - Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin.php.
Mögliche Gegenmaßnahme
Mingle Forum: Update to version 1.0.34, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Mingle Forum
Version
*-1.0.33.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cartpauj ≫ Mingle-forum Version <= 1.0.33
Cartpauj ≫ Mingle-forum Version1.0.00
Cartpauj ≫ Mingle-forum Version1.0.01
Cartpauj ≫ Mingle-forum Version1.0.02
Cartpauj ≫ Mingle-forum Version1.0.03
Cartpauj ≫ Mingle-forum Version1.0.04
Cartpauj ≫ Mingle-forum Version1.0.05
Cartpauj ≫ Mingle-forum Version1.0.06
Cartpauj ≫ Mingle-forum Version1.0.07
Cartpauj ≫ Mingle-forum Version1.0.08
Cartpauj ≫ Mingle-forum Version1.0.09
Cartpauj ≫ Mingle-forum Version1.0.10
Cartpauj ≫ Mingle-forum Version1.0.11
Cartpauj ≫ Mingle-forum Version1.0.12
Cartpauj ≫ Mingle-forum Version1.0.13
Cartpauj ≫ Mingle-forum Version1.0.14
Cartpauj ≫ Mingle-forum Version1.0.15
Cartpauj ≫ Mingle-forum Version1.0.16
Cartpauj ≫ Mingle-forum Version1.0.17
Cartpauj ≫ Mingle-forum Version1.0.18
Cartpauj ≫ Mingle-forum Version1.0.19
Cartpauj ≫ Mingle-forum Version1.0.20
Cartpauj ≫ Mingle-forum Version1.0.21
Cartpauj ≫ Mingle-forum Version1.0.21.1
Cartpauj ≫ Mingle-forum Version1.0.22
Cartpauj ≫ Mingle-forum Version1.0.23
Cartpauj ≫ Mingle-forum Version1.0.23.1
Cartpauj ≫ Mingle-forum Version1.0.23.2
Cartpauj ≫ Mingle-forum Version1.0.24
Cartpauj ≫ Mingle-forum Version1.0.25
Cartpauj ≫ Mingle-forum Version1.0.26
Cartpauj ≫ Mingle-forum Version1.0.27
Cartpauj ≫ Mingle-forum Version1.0.28
Cartpauj ≫ Mingle-forum Version1.0.28.1
Cartpauj ≫ Mingle-forum Version1.0.28.2
Cartpauj ≫ Mingle-forum Version1.0.29
Cartpauj ≫ Mingle-forum Version1.0.30
Cartpauj ≫ Mingle-forum Version1.0.31
Cartpauj ≫ Mingle-forum Version1.0.31.1
Cartpauj ≫ Mingle-forum Version1.0.31.2
Cartpauj ≫ Mingle-forum Version1.0.31.3
Cartpauj ≫ Mingle-forum Version1.0.31.4
Cartpauj ≫ Mingle-forum Version1.0.32
Cartpauj ≫ Mingle-forum Version1.0.32.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.597 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.