{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-17T04:42:08.858","vulnerabilities":[{"cve":{"id":"CVE-2013-7351","sourceIdentifier":"security@debian.org","published":"2020-01-02T20:15:15.130","lastModified":"2024-11-21T02:00:48.770","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks."},{"lang":"es","value":"Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en el archivo index.php en Shaarli permiten a atacantes remotos inyectar script web o HTML arbitrario por medio de la URL en la función (1) showRSS, (2) showATOM o (3) showDailyRSS; un (4) nombre de archivo en la función importFile; o (5) vectores relacionados con marcadores."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:shaarli_project:shaarli:-:*:*:*:*:*:*:*","matchCriteriaId":"9D0345D4-5FA4-40FD-B35E-226B4EA356AE"}]}]}],"references":[{"url":"http://seclists.org/oss-sec/2014/q2/1","source":"security@debian.org","tags":["Exploit","Mailing List","Patch","Third Party Advisory"]},{"url":"http://seclists.org/oss-sec/2014/q2/4","source":"security@debian.org","tags":["Exploit","Mailing List","Patch","Third Party Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92215","source":"security@debian.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a","source":"security@debian.org","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/sebsauvage/Shaarli/issues/134","source":"security@debian.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://seclists.org/oss-sec/2014/q2/1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mailing List","Patch","Third Party Advisory"]},{"url":"http://seclists.org/oss-sec/2014/q2/4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mailing List","Patch","Third Party Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/92215","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://github.com/sebsauvage/Shaarli/commit/53da201749f8f362323ef278bf338f1d9f7a925a","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/sebsauvage/Shaarli/issues/134","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}