MEDIUM
Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme."
Published Jun 17, 2013
4.3
MEDIUMCVSS 2.0
EPSS 1.15%
Description
Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme."
Affected products
No data.
Configuration 1
OR
- 3.4
- 3.4.0
- 3.4.0.1
- 3.4.1
- 3.4.1.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.4.1
- 3.4.5
- 3.4.6
- 3.4.6.1
- 3.4.6.2
- 3.4.7
- 3.4.8
- 3.4.9
- 3.4.9.1
- 3.4.9.2
- 3.4.10
- 3.4.11
- 3.4.11.1
- 3.4.12
- 3.4.12.1
- 3.4.13
- 3.4.14
- 3.4.14.1
- 3.4.15
- 3.4.15.1
- 3.4.16
- 3.4.17
- 3.4.18
- 3.4.19
- 3.4.21
- 3.4b
Configuration 2
OR
- 3.6.0
- 3.6.1
- 3.6.2
- 3.6.3
- 3.6.4
- 3.6.5
- 3.6.6
- 3.6.7
- 3.6.8
- 3.6.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://jvn.jp/en/jp/JVN18501376/index.html third-party-advisoryx_refsource_JVN
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000038 third-party-advisoryx_refsource_JVNDB
- http://www.openpne.jp/archives/11096/ x_refsource_CONFIRMPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2255 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://jvn.jp/en/jp/JVN18501376/index.html | third-party-advisoryx_refsource_JVN | |
| http://jvndb.jvn.jp/jvndb/JVNDB-2013-000038 | third-party-advisoryx_refsource_JVNDB | |
| http://www.openpne.jp/archives/11096/ | x_refsource_CONFIRMPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2255 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner jpcert
Published Jun 17, 2013
Updated Sep 16, 2024
Reserved Mar 4, 2013
Link CVE-2013-2309
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data