CVE-2013-1413: I-Doit
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when the 'sanitize user input' flag is not enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- I-Doit I-Doit: up to and including 1.0; version 0.9.9 only; version 1.0.2 only
Published 2014-02-11. Last modified 2026-06-16.