PT-2013-3556 · Apache · Apache Open For Business Project

Published

2013-08-15

·

Updated

2018-05-18

·

CVE-2013-2137

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Open For Business Project (aka OFBiz) versions 10.04.01 through 10.04.05 Apache Open For Business Project (aka OFBiz) versions 11.04.01 through 11.04.02 Apache Open For Business Project (aka OFBiz) version 12.04.01
Description A cross-site scripting (XSS) issue exists in the Webtools application, specifically in the "View Log" screen, allowing remote attackers to inject arbitrary web script or HTML.
Recommendations For versions 10.04.01 through 10.04.05, update to a version outside of this range to resolve the issue. For versions 11.04.01 through 11.04.02, update to a version outside of this range to resolve the issue. For version 12.04.01, update to a version later than 12.04.01 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2137

Affected Products

Apache Open For Business Project