CVE-2013-4167
Published Oct 11, 2013
Last updated 11 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) before 1.11.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC15CE10-4ABB-4277-8CAC-D714A02BA4E9", "versionEndIncluding": "1.11.6" }, { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "578303F3-6729-45A9-8DBE-A2C393E7BB2A" }, { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93A32CE1-85A4-417F-90D4-1378B61A45E6" }, { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D63AC3D8-0297-423B-9D50-59F7B1582348" }, { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "272A22FB-4553-47FD-88D6-B2D0C096F6EE" }, { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C57412ED-477E-463D-91AB-CC02149A6E23" }, { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2AB67E7-4528-4AE0-9B60-DD5B1B71D17E" }, { "criteria": "cpe:2.3:a:cmsmadesimple:cms_made_simple:1.11.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CD8DAF5-2EE2-40D2-9DFA-1D2BA749757D" } ], "operator": "OR" } ] } ]