{"api_version":"1","generated_at":"2026-07-23T10:17:33+00:00","cve":"CVE-2013-7231","urls":{"html":"https://cve.report/CVE-2013-7231","api":"https://cve.report/api/cve/CVE-2013-7231.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-7231","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-7231"},"summary":{"title":"CVE-2013-7231","description":"Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222.","state":"PUBLISHED","assigner":"mitre","published_at":"2013-12-30 04:53:07","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://support.esri.com/en/knowledgebase/techarticles/detail/41468","name":"http://support.esri.com/en/knowledgebase/techarticles/detail/41468","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"41468 - NIM092820: Mobile Content Server has a cross-site scripting vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.esri.com/en/downloads/patches-servicepacks/view/productid/66/metaid/2009","name":"http://support.esri.com/en/downloads/patches-servicepacks/view/productid/66/metaid/2009","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ArcGIS 10.2 for Server Security Patch (September 2013) | Samples and Utilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-7231","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7231","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"7231","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"esri","cpe5":"arcgis_server","cpe6":"10.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"7231","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"esri","cpe5":"arcgis_server","cpe6":"10.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"7231","cve":"CVE-2013-7231","epss":"0.001720000","percentile":"0.381530000","score_date":"2026-04-30","updated_at":"2026-05-01 00:10:53"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:01:19.566Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.esri.com/en/knowledgebase/techarticles/detail/41468"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.esri.com/en/downloads/patches-servicepacks/view/productid/66/metaid/2009"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2013-12-30T02:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.esri.com/en/knowledgebase/techarticles/detail/41468"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.esri.com/en/downloads/patches-servicepacks/view/productid/66/metaid/2009"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2013-7231","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.esri.com/en/knowledgebase/techarticles/detail/41468","refsource":"CONFIRM","url":"http://support.esri.com/en/knowledgebase/techarticles/detail/41468"},{"name":"http://support.esri.com/en/downloads/patches-servicepacks/view/productid/66/metaid/2009","refsource":"CONFIRM","url":"http://support.esri.com/en/downloads/patches-servicepacks/view/productid/66/metaid/2009"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2013-7231","datePublished":"2013-12-30T02:00:00.000Z","dateReserved":"2013-12-29T00:00:00.000Z","dateUpdated":"2024-09-17T01:21:00.243Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-12-30 04:53:07","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:esri:arcgis_server:10.1:*:*:*:*:*:*:*","matchCriteriaId":"9177A95B-4A0A-42D7-9792-E58CC2207021"},{"vulnerable":true,"criteria":"cpe:2.3:a:esri:arcgis_server:10.2:*:*:*:*:*:*:*","matchCriteriaId":"E93A0EA7-1DCB-465F-A34B-44CC8294EE67"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"7231","Ordinal":"1","Title":"CVE-2013-7231","CVE":"CVE-2013-7231","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"7231","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222.","Type":"Description","Title":"CVE-2013-7231"},{"CveYear":"2013","CveId":"7231","Ordinal":"2","NoteData":"2013-12-29","Type":"Other","Title":"Published"}]}}}