Description
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 13 Feb 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Caseproof
Caseproof prettylinks |
|
| CPEs | cpe:2.3:a:blair_williams:pretty_link_lite:1.6.0:*:*:*:*:*:*:* cpe:2.3:a:blair_williams:pretty_link_lite:1.6.1:*:*:*:*:*:*:* |
cpe:2.3:a:caseproof:prettylinks:*:*:*:*:*:*:*:* cpe:2.3:a:caseproof:prettylinks:1.6.0:*:*:*:*:*:*:* cpe:2.3:a:caseproof:prettylinks:1.6.1:*:*:*:*:*:*:* |
| Vendors & Products |
Blair Williams
Blair Williams pretty Link Lite |
Caseproof
Caseproof prettylinks |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T15:13:31.662Z
Reserved: 2013-02-07T00:00:00.000Z
Link: CVE-2013-1636
No data.
Status : Modified
Published: 2014-03-12T14:55:26.600
Modified: 2026-05-06T22:30:45.220
Link: CVE-2013-1636
No data.
OpenCVE Enrichment
No data.
Weaknesses