Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php in the htmlarea SpellChecker module, as used in Serendipity before 1.7.3 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the to_r_list parameter.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:14:54

Updated: 2022-10-03T16:14:54

Reserved: 2022-10-03T00:00:00


Link: CVE-2013-5670

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2013-11-05T18:55:06.167

Modified: 2013-11-07T01:23:31.863


Link: CVE-2013-5670

JSON object: View

cve-icon Redhat Information

No data.

CWE