Unrated severityNVD Advisory· Published Dec 31, 2013· Updated Jun 17, 2026
CVE-2013-7241
CVE-2013-7241
Description
Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:zenphoto:zenphoto:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:zenphoto:zenphoto:*:*:*:*:*:*:*:*range: <=1.4.5.3
- cpe:2.3:a:zenphoto:zenphoto:1.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:zenphoto:zenphoto:1.4.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:zenphoto:zenphoto:1.4.5.2:*:*:*:*:*:*:*
- (no CPE)range: <1.4.5.4
Patches
Vulnerability mechanics
References
6- openwall.com/lists/oss-security/2013/12/29/1nvdExploit
- seclists.org/bugtraq/2013/Oct/20nvdExploit
- www.zenphoto.org/news/zenphoto-1.4.5.4nvdVendor Advisory
- www.enkomio.com/Advisory/SOJOBO-ADV-13-01nvdURL Repurposed
- openwall.com/lists/oss-security/2013/12/30/10nvd
- www.securityfocus.com/bid/62815nvd
News mentions
0No linked articles in our index yet.