Cross-site Scripting Vulnerability in Elgg's Twitter Widget
CVE-2013-0234

Currently unrated

Key Information:

Vendor

Elgg

Status
Vendor
CVE Published:
2 February 2014

What is CVE-2013-0234?

The Twitter widget in Elgg prior to versions 1.7.17 and 1.8.13 is vulnerable to Cross-site Scripting (XSS). This vulnerability allows remote attackers to inject arbitrary web scripts or HTML through the 'params[twitter_username]' parameter used in the action/widgets/save functionality. Successful exploitation can lead to unauthorized actions and data exposure, highlighting the need for immediate updates to secure user interactions with the widget.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.