CVE-2013-0933: XSS
Published May 7, 2013
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
6 affected components
EMC Rsa Archer Egrc=5.0
EMC Rsa Archer Egrc=5.1
EMC Rsa Archer Egrc=5.2
EMC Rsa Archer Egrc=5.3
EMC RSA Archer SmartSuite=4.3
EMC RSA Archer SmartSuite=4.5
Event History
May 7, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0933?
CVE-2013-0933 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2013-0933?
To fix CVE-2013-0933, upgrade EMC RSA Archer to version 5.3SP1 or later.
3
What products are affected by CVE-2013-0933?
CVE-2013-0933 affects EMC RSA Archer versions 5.0 through 5.3 and Archer Smart Suite Framework versions 4.x.
4
Can CVE-2013-0933 be exploited remotely?
Yes, CVE-2013-0933 can be exploited remotely by attackers to inject arbitrary web scripts.
5
What are common mitigation strategies for CVE-2013-0933?
Common mitigation strategies for CVE-2013-0933 include input validation and using web application firewalls.