Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-4954


Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a register action. NOTE: some of these details are obtained from third party information.


Published

2013-07-29T23:27:50.317

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.6 (LOW)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

4.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application genetechsolutions pie-register ≤ 1.30 Yes
Application genetechsolutions pie-register 1.0.1 Yes
Application genetechsolutions pie-register 1.1.1 Yes
Application genetechsolutions pie-register 1.1.2 Yes
Application genetechsolutions pie-register 1.1.3 Yes
Application genetechsolutions pie-register 1.1.5 Yes
Application genetechsolutions pie-register 1.1.6 Yes
Application genetechsolutions pie-register 1.1.7 Yes
Application genetechsolutions pie-register 1.1.8 Yes
Application genetechsolutions pie-register 1.1.9 Yes
Application genetechsolutions pie-register 1.1.9 Yes
Application genetechsolutions pie-register 1.2.0 Yes
Application genetechsolutions pie-register 1.2.1 Yes
Application genetechsolutions pie-register 1.2.2 Yes
Application genetechsolutions pie-register 1.2.3 Yes
Application genetechsolutions pie-register 1.2.4 Yes
Application genetechsolutions pie-register 1.2.6 Yes
Application genetechsolutions pie-register 1.2.7 Yes
Application genetechsolutions pie-register 1.2.8 Yes
Application genetechsolutions pie-register 1.2.9 Yes
Application genetechsolutions pie-register 1.2.9 Yes
Application genetechsolutions pie-register 1.2.91 Yes
Application wordpress wordpress - No

References