CVE-2013-2137: XSS
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2137?
CVE-2013-2137 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-2137?
To fix CVE-2013-2137, upgrade to the latest version of Apache OFBiz that addresses this vulnerability.
What systems are affected by CVE-2013-2137?
Apache OFBiz versions 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 are affected by CVE-2013-2137.
What type of vulnerability is CVE-2013-2137?
CVE-2013-2137 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary scripts.
What are the possible impacts of CVE-2013-2137?
The impacts of CVE-2013-2137 include potential data theft, session hijacking, and unauthorized actions performed on behalf of users.