4.3
CVSSv2

CVE-2013-7241

Published: 31/12/2013 Updated: 14/02/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto prior to 1.4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the URI.

Vulnerable Product Search on Vulmon Subscribe to Product

zenphoto zenphoto

zenphoto zenphoto 1.4.5.1

zenphoto zenphoto 1.4.5.2

zenphoto zenphoto 1.4.5