First published: Thu Aug 15 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OFBiz | =10.04.01 | |
Apache OFBiz | =10.04.02 | |
Apache OFBiz | =10.04.03 | |
Apache OFBiz | =10.04.04 | |
Apache OFBiz | =10.04.05 | |
Apache OFBiz | =11.04.01 | |
Apache OFBiz | =11.04.02 | |
Apache OFBiz | =12.04.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2137 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2013-2137, upgrade to the latest version of Apache OFBiz that addresses this vulnerability.
Apache OFBiz versions 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 are affected by CVE-2013-2137.
CVE-2013-2137 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary scripts.
The impacts of CVE-2013-2137 include potential data theft, session hijacking, and unauthorized actions performed on behalf of users.