Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7033

Опубликовано: 06 сент. 2016
Источник: redhat
CVSS3: 4.2
CVSS2: 4
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via dashbuilder. Remote, authenticated attackers that have privileges to access dashbuilder (usually admins) can store scripts in several editable fields, which are not properly sanitized before showing to other users, including other admins.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6dashbuilderAffected
Red Hat JBoss BRMS 6dashbuilderNot affected
Red Hat JBoss BPMS 6.4FixedRHSA-2017:024902.02.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79

EPSS

Процентиль: 73%
0.01543
Низкий

4.2 Medium

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
nvd
почти 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
github
больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS

Процентиль: 73%
0.01543
Низкий

4.2 Medium

CVSS3

4 Medium

CVSS2