← Back

CVE-2013-5670

nvd nist
Published: Nov 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php in the htmlarea SpellChecker module, as used in Serendipity before 1.7.3 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the to_r_list parameter.

Affected (38)

Products: S9y: Serendipity
1 product
Serendipity
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
S9y
Up to 1.7.2
Version 0.3
Version 0.4
Version 0.7.1
Version 0.7
Version 0.8.1
Version 0.8.2
Version 0.8.3
Version 0.8.4
Version 0.8.5
Version 0.8
Version 0.9.1
Version 0.9
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1
Version 1.2.1
Version 1.2
Version 1.3.1
Version 1.3
Version 1.4.1
Version 1.4
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.4
Version 1.5.5
Version 1.6.1
Version 1.6.2
Version 1.6
Version 1.7

References (10)

Timeline

No history available yet.