Unrated severityNVD Advisory· Published Sep 9, 2013· Updated Apr 29, 2026
CVE-2013-4899
CVE-2013-4899
Description
Cross-site scripting (XSS) vulnerability in Twilight CMS 5.17 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the gallery/ page.
Affected products
2cpe:2.3:a:twilightcms:twilight_cms:*:*:*:en:*:*:*:*+ 1 more
- cpe:2.3:a:twilightcms:twilight_cms:*:*:*:en:*:*:*:*range: <=5.17
- cpe:2.3:a:twilightcms:twilight_cms:*:*:*:ru:*:*:*:*range: <=5.17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- archives.neohapsis.com/archives/bugtraq/2013-08/0128.htmlnvdExploit
- www.htbridge.com/advisory/HTB23166nvdExploit
- secunia.com/advisories/54404nvdVendor Advisory
News mentions
0No linked articles in our index yet.