Medium severity6.1NVD Advisory· Published Dec 31, 2013· Updated Jun 16, 2026
CVE-2013-3572
CVE-2013-3572
Description
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:ui:unifi_controller:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ui:unifi_controller:*:*:*:*:*:*:*:*range: <2.3.6
- (no CPE)range: <=2.3.5
Patches
Vulnerability mechanics
References
4- dl.ubnt.com/unifi/static/cve-2013-3572.htmlnvdVendor Advisory
- www.securityfocus.com/bid/64601nvdBroken LinkThird Party AdvisoryVDB Entry
- community.ubnt.com/t5/UniFi/Security-Advisory-CVE-2013-3572/m-p/601047nvdVendor Advisory
- spaceblogs.org/shackspace/2013/10/shackspace-hacker-finds-flaw-in-ubiquiti-networks-unifi-products/nvdBroken LinkURL Repurposed
News mentions
0No linked articles in our index yet.