PT-2013-5004 · Red Hat · Red Hat Enterprise Mrg Grid

Tomáš Nováčik

·

Published

2013-12-23

·

Updated

2023-02-13

·

CVE-2013-4414

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise MRG Grid version 2.4
Description A cross-site scripting (XSS) issue exists in the web interface for cumin, allowing remote attackers to inject arbitrary web script or HTML via the Max allowance field in the "Set limit" form.
Recommendations For Red Hat Enterprise MRG Grid version 2.4, update the software to a version that includes a fix for this issue, as no specific workaround is provided.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2013-4414
RHSA-2013:1851
RHSA-2013:1852

Affected Products

Red Hat Enterprise Mrg Grid