AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-4170

MEDIUM · CVSS 6.1 EPSS 0.87%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-30 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It affects Java.

CVE
CVE-2013-4170
Severity
MEDIUM
CVSS
6.1
EPSS
0.87%
Java

Original NVD Description

In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into such a string without being sanitized. This means that if an application assigns a view's `tagName` to user-supplied data, a specially-crafted payload could execute arbitrary JavaScript in the context of the current domain ("XSS"). This vulnerability only affects applications that assign or bind user-provided content to `tagName`.

Related CVEs

Other vulnerabilities affecting the same vendor(s)