cbcvebase.
CVE-2013-4722
published 2014-04-25

CVE-2013-4722: Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.85%
76.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) url, (3) qstr parameter.

Affected

4 ranges
VendorProductVersion rangeFixed in
ddsncm3_acora_content_management_system
ddsncm3_acora_content_management_system
ddsncm3_acora_content_management_system
ddsncm3_acora_content_management_system
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.