Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Freebsd | — | Upgrade jenkins | Dec 10, 2025 | May 3, 2013 |
| Jenkins 2013 05 02 | — | Upgrade Jenkins LTS to version 1.509.1Upgrade Jenkins to version 1.514Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest version | Nov 13, 2017 | Mar 28, 2013 |
| Redhat Openshift | — | Upgrade jenkins | Oct 8, 2019 | Apr 2, 2013 |
| Zopim Live Chat Plugin | — | Update zopim-live-chat plugin to version 1.2.6, or a newer patched version | May 15, 2025 | Feb 18, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub