CVE-2013-4241
Summary
| CVE | CVE-2013-4241 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-30 21:15:00 UTC |
| Updated | 2020-02-03 21:02:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page). |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hitmyserver | Hms Testimonials | All | All | All | All |
| Application | Hitmyserver | Hms Testimonials | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: [RCA-201308-01] HMS Testimonials 2.0.10 WP plugin - Multiple vulnerabilities | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| oss-sec: Re: Re: CVE Request - HMS Testimonials 2.0.10 WP plugin | MISC | seclists.org | Mailing List, Third Party Advisory |
| oss-sec: CVE Request - HMS Testimonials 2.0.10 WP plugin | MISC | seclists.org | Mailing List, Third Party Advisory |
| WordPress › HMS Testimonials « WordPress Plugins | MISC | wordpress.org | Release Notes |
| Full Disclosure: Update [RCA-201309-01] HMS Testimonials 2.0.10 WP plugin - Multiple vulnerabilities | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.