CVE-2013-7188
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
4.3
Description
Cross-site scripting (XSS) vulnerability in KBKP Software HostBill before 2013-12-14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hostbillapp | hostbill | {"endIncluding":"13-12-2013"} | |
| hostbillapp | hostbill | 02-08-2013 | |
| hostbillapp | hostbill | 04-11-2013 | |
| hostbillapp | hostbill | 4.7.0 | |
| hostbillapp | hostbill | 4.7.2 | |
| hostbillapp | hostbill | 4.7.4 | |
| hostbillapp | hostbill | 4.7.6 | |
| hostbillapp | hostbill | 4.7.8 | |
| hostbillapp | hostbill | 4.8.0 | |
| hostbillapp | hostbill | 4.8.2 | |
| hostbillapp | hostbill | 4.8.4 | |
| hostbillapp | hostbill | 4.8.6 | |
| hostbillapp | hostbill | 4.8.8 | |
| hostbillapp | hostbill | 4.9.0 | |
| hostbillapp | hostbill | 4.9.6 | |
| hostbillapp | hostbill | 4.9.8 | |
| hostbillapp | hostbill | 06-11-2013 | |
| hostbillapp | hostbill | 06-12-2013 | |
| hostbillapp | hostbill | 08-11-2013 | |
| hostbillapp | hostbill | 15-11-2013 | |
| hostbillapp | hostbill | 18-10-2013 | |
| hostbillapp | hostbill | 19-11-2013 | |
| hostbillapp | hostbill | 22-11-2013 | |
| hostbillapp | hostbill | 25-10-2013 | |
| hostbillapp | hostbill | 29-11-2013 | |
References
- http://extras.hostbillapp.com/security-advisory-hostbill-version-2013-12-14/
- http://hostbillapp.com/changelog
- http://osvdb.org/101030
- http://secunia.com/advisories/56124
- https://blog.rack911.com/security-advisories/hostbill-xss-admin-hijack-security-vulnerability-r911-0099
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89750
- http://extras.hostbillapp.com/security-advisory-hostbill-version-2013-12-14/
- http://hostbillapp.com/changelog
- http://osvdb.org/101030
- http://secunia.com/advisories/56124
- https://blog.rack911.com/security-advisories/hostbill-xss-admin-hijack-security-vulnerability-r911-0099
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89750
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.