First published: Thu Dec 31 2009(Updated: )
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse BIRT | <=2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4521 is considered a medium-severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-4521, upgrade to Eclipse BIRT version 2.5.0 or later, which addresses the XSS vulnerability.
CVE-2009-4521 affects versions of Eclipse BIRT up to 2.3.2, including implementations in products like KonaKart.
CVE-2009-4521 is classified as a cross-site scripting (XSS) vulnerability.
Yes, attackers can exploit CVE-2009-4521 remotely to inject arbitrary web scripts or HTML.