#VU42095 Cross-site scripting in SPIP - CVE-2013-7303
Published: January 30, 2014 / Updated: February 14, 2021
SPIP
spip.net
Description
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 when processing the author name field. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- http://core.spip.org/projects/spip/repository/revisions/20902
- http://seclists.org/oss-sec/2014/q1/123
- http://seclists.org/oss-sec/2014/q1/128
- http://secunia.com/advisories/56381
- http://www.securitytracker.com/id/1029703
- http://www.spip.net/fr_article5648.html
- http://www.spip.net/fr_article5665.html
- http://zone.spip.org/trac/spip-zone/changeset/77768
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90643