CVE-2013-1413: I-Doit

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when the 'sanitize user input' flag is not enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected products

  • I-Doit I-Doit: up to and including 1.0; version 0.9.9 only; version 1.0.2 only

Published 2014-02-11. Last modified 2026-06-16.