Medium severity6.1NVD Advisory· Published Dec 31, 2013· Updated Apr 29, 2026
CVE-2013-3572
CVE-2013-3572
Description
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- dl.ubnt.com/unifi/static/cve-2013-3572.htmlnvdVendor Advisory
- www.securityfocus.com/bid/64601nvdBroken LinkThird Party AdvisoryVDB Entry
- community.ubnt.com/t5/UniFi/Security-Advisory-CVE-2013-3572/m-p/601047nvdVendor Advisory
- spaceblogs.org/shackspace/2013/10/shackspace-hacker-finds-flaw-in-ubiquiti-networks-unifi-products/nvdBroken LinkURL Repurposed
News mentions
0No linked articles in our index yet.