CVE-2013-7062

Description

Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote attackers to inject arbitrary web script or HTML via unspecified input in the (1) browser_id_manager or (2) OFS.Image method.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.763

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2010-2422,CVE-2011-1949,CVE-2011-2528,CVE-2013-7062 are fixed in Python-plone 3.3.6Windows
Multiple vulnerabilities are fixed in Python-plone 4.3.2Windows
Vulnerabilities CVE-2013-7062 are fixed in Python-plone 4.0.9Windows
Vulnerabilities CVE-2013-7062 are fixed in Python-plone 4.1.6Windows
Vulnerabilities CVE-2010-2422,CVE-2011-1949,CVE-2011-2528,CVE-2013-7062 are fixed in Python-plone for linux 3.3.6Linux
Multiple vulnerabilities are fixed in Python-plone for linux 4.3.2Linux
Vulnerabilities CVE-2013-7062 are fixed in Python-plone for linux 4.0.9Linux
Vulnerabilities CVE-2013-7062 are fixed in Python-plone for linux 4.1.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234