Security Advisory

CVE-2013-3529

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2013-05-10 21:00:00
Last updated 2024-08-06 16:14:55
Assigner mitre
State PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message parameter.