CVE-2013-7241
31.12.2013, 15:16
Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.
Vendor | Product | Version |
---|---|---|
zenphoto | zenphoto | 𝑥 ≤ 1.4.5.3 |
zenphoto | zenphoto | 1.4.5 |
zenphoto | zenphoto | 1.4.5.1 |
zenphoto | zenphoto | 1.4.5.2 |
𝑥
= Vulnerable software versions
References