CVE-2013-5315
Last modified
CVE-2013-5315 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6.x-1.x before 6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the atom title, a different vector than CVE-2013-4174.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6.x-1.x before 6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the atom title, a different vector than CVE-2013-4174.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ows | Scald | 6.x-1.0 | Alpha1 |
| Ows | Scald | 6.x-1.x | Dev |
| Ows | Scald | 7.x-1.0 | — |
References
- http://secunia.com/advisories/54144Vendor Advisory
- https://drupal.org/node/2049415Patch, Vendor Advisory
- http://secunia.com/advisories/54144Vendor Advisory
- https://drupal.org/node/2049415Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-5315?
How severe is CVE-2013-5315?
How do I fix CVE-2013-5315?
Are you affected by CVE-2013-5315?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
