Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7033

Опубликовано: 06 сент. 2016
Источник: redhat
CVSS3: 4.2
CVSS2: 4

Описание

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via dashbuilder. Remote, authenticated attackers that have privileges to access dashbuilder (usually admins) can store scripts in several editable fields, which are not properly sanitized before showing to other users, including other admins.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6dashbuilderAffected
Red Hat JBoss BRMS 6dashbuilderNot affected
Red Hat JBoss BPMS 6.4FixedRHSA-2017:024902.02.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79

4.2 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
nvd
больше 9 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
github
больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.2 Medium

CVSS3

4 Medium

CVSS2