CVE-2013-2309
Estado: ModificadaMedia (4.3)—
Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme."
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.15%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-2309",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-06-17T03:29:44.093",
"references": [
{
"url": "http://jvn.jp/en/jp/JVN18501376/index.html",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000038",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.openpne.jp/archives/11096/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://jvn.jp/en/jp/JVN18501376/index.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000038",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openpne.jp/archives/11096/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the \"mobile version color scheme.\""
},
{
"lang": "es",
"value": "Vulnerabilidad XSS en la pantalla de gestión de OpenPNE 3.4.x anteior a 3.4.21.1, 3.6.x anterior a 3.6.9.1, y 3.8.x anterior a 3.8.5.1,\r\npermite a atacantes remotos inyectar secuencias arbitrarias de comandos web o HTML a través de vectores que involucran a la \"versión del esquema de color móvil\"."
}
],
"lastModified": "2026-06-16T23:53:06.740",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1ABB1D4F-1030-4FDA-9F76-8AFFDAE2AD7F"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30F1CE69-1510-49E6-AA85-6C9FB171C1FB"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5FDFF3C-C266-4B7D-9EF2-C7157BDEAC0A"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75A5B71B-CC3F-4027-9B7D-4E871FFB0F1C"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6F151AF-E151-4712-BA46-73E08CFB7E3A"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C31EECCE-9D97-4E73-AE38-1452617CBA5C"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C15DE721-B309-4DB8-B3EF-91A0B3A506B3"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E1F0D12-4D9F-4D9D-AE17-1C20A29407A6"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C43A1D0F-1388-405A-AA63-ED6FF470492C"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAFD674B-5FAA-4A73-B98D-4DE1F9416603"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "054B5BB3-839A-479A-B3F4-0138E69BB91C"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BBB540F-13AA-4C1C-A4DC-776A6159E57B"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D339E485-05CD-47D5-8BB5-D310A35FDEDA"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE17BE24-B19F-43D7-911B-DA1C29761C12"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AC86116-CEE9-4649-B23F-A9A05B305479"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D46F963A-F39E-413D-99DB-9CA1DEF8F0E3"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4225D03-C36B-479D-BD64-4901BDF7F9E5"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.9.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45E85C7B-9B74-4203-90ED-5B58F2944979"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9E7C7CA-3F38-4A97-ABB6-209234B6B828"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A46AD478-06AA-41CF-AA67-2A1C7D6EAF4E"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.11.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C555B92A-7463-40CF-A8AB-F161EA7F2563"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "53154000-87D9-4443-BCDE-5FF543B1FEE9"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.12.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E31EF04D-A8CD-4619-987D-E36DC9D83F60"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18331AA6-0200-4E3A-9FAE-271CFED0B214"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E86563C-FE1C-4DDF-B6C1-80B8FB5A7D46"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.14.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCE21F7D-2EB5-4447-8394-F22249079E04"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "939A339B-220A-4585-BEFD-5B5C88D596F6"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.15.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1ABA7F36-1675-4CE0-9D02-CD9B366556B7"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31D62BF5-1050-4C61-97EA-1F1BAAF484DA"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75E95236-144B-48A0-9DF6-9FAEC12A01F5"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFD16C57-1C68-432B-9345-7FDF42CA7CA0"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58CABFCA-F4A3-435C-A5CB-DBC534066FBD"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC00CCC6-0834-4FAD-82CB-45F23366944F"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.4b:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62F9FBD5-3AF7-4008-A4B8-CC755687C58C"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "595424AD-700E-4DA1-81E8-1ADBD4E3B00B"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE15148F-80E3-4446-99A3-0F93A55F1F80"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58DB7FFF-A505-4A17-A315-DAD95D61C166"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89C6F9FC-8C4E-4CEC-BE5B-324CC90E0EE3"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C10B98DA-069C-46AC-87C8-B51CB022E581"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BDD02F8-CB23-4397-8A41-44BE9925238D"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8EBCE5F3-C4FE-4619-A085-D9F008168982"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2E36111-87F4-4FC8-85F4-B7482843494D"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E877FC0-CDA4-4335-8A4D-5FD375AD6D7B"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBBF5F4E-2BD6-42CC-9BCD-B794EDA7193E"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2EE094E-81D8-4417-8A77-6F11AEF7614C"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42B44ECD-DA1E-4B91-846E-19240690969A"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26A124D4-EE08-4CB7-845F-5E88E2EC8D0A"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71F39F10-2C66-4A9F-A759-70FD217E4646"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17D56C3D-E96A-49C4-91E0-ADC7B2E2EEA5"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "368A4FCC-D252-4832-9521-13ABC77BA22D"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEC0E461-714C-413B-B552-AD3EF1CE46DD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}