CVE-2013-7351
Estado: ModificadaMedia (6.1)—
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.21%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://seclists.org/oss-sec/2014/q2/1
- http://seclists.org/oss-sec/2014/q2/4
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92215
- https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a
- https://github.com/sebsauvage/Shaarli/issues/134
- http://seclists.org/oss-sec/2014/q2/1
- http://seclists.org/oss-sec/2014/q2/4
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92215
- https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a
- https://github.com/sebsauvage/Shaarli/issues/134
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-7351",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@debian.org",
"affectedData": [
{
"vendor": "Shaarli",
"product": "Shaarli",
"versions": [
{
"status": "affected",
"version": "before 53da201749f8f362323ef278bf338f1d9f7a925a"
}
]
}
]
}
],
"published": "2020-01-02T20:15:15.130",
"references": [
{
"url": "http://seclists.org/oss-sec/2014/q2/1",
"tags": [
"Exploit",
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "security@debian.org"
},
{
"url": "http://seclists.org/oss-sec/2014/q2/4",
"tags": [
"Exploit",
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "security@debian.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/92215",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security@debian.org"
},
{
"url": "https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security@debian.org"
},
{
"url": "https://github.com/sebsauvage/Shaarli/issues/134",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "security@debian.org"
},
{
"url": "http://seclists.org/oss-sec/2014/q2/1",
"tags": [
"Exploit",
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/oss-sec/2014/q2/4",
"tags": [
"Exploit",
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/92215",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/sebsauvage/Shaarli/issues/134",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en el archivo index.php en Shaarli permiten a atacantes remotos inyectar script web o HTML arbitrario por medio de la URL en la función (1) showRSS, (2) showATOM o (3) showDailyRSS; un (4) nombre de archivo en la función importFile; o (5) vectores relacionados con marcadores."
}
],
"lastModified": "2026-06-17T00:01:48.623",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:shaarli_project:shaarli:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D0345D4-5FA4-40FD-B35E-226B4EA356AE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@debian.org"
}