CVE-2013-3640: XSS
Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 12 and Pro Advanced before 12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3640?
CVE-2013-3640 is classified as a cross-site scripting (XSS) vulnerability, which poses a moderate risk as it allows attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2013-3640?
To mitigate CVE-2013-3640, users should update to a version of FileMaker Pro or Pro Advanced that is 12.0 or higher, as this will eliminate the vulnerability.
What products are affected by CVE-2013-3640?
CVE-2013-3640 affects FileMaker Pro and FileMaker Pro Advanced versions prior to 12.0, including versions 8.0 through 11.0.4.
Can attackers exploit CVE-2013-3640 without authentication?
Yes, CVE-2013-3640 can be exploited by remote attackers without the need for authentication, making it particularly concerning.
What types of attacks can CVE-2013-3640 facilitate?
CVE-2013-3640 can facilitate cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in the context of a user's browser.