CVE-2013-3281: XSS
Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2 P07, and Documentum Capital Projects before 1.8 P01 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter in a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3281?
CVE-2013-3281 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-3281?
To fix CVE-2013-3281, upgrade to the latest supported versions of the affected software such as Documentum Webtop 6.7 SP2 P07 or later.
Which versions are affected by CVE-2013-3281?
CVE-2013-3281 affects versions of Documentum Webtop, WDK, Taskspace, and other related software prior to their respective SP2 updates.
What type of vulnerability is CVE-2013-3281?
CVE-2013-3281 is a cross-site scripting (XSS) vulnerability which can allow attackers to execute arbitrary scripts in the context of a user's browser.
Is CVE-2013-3281 being exploited in the wild?
At the time of reporting, there was no public information confirming active exploitation of CVE-2013-3281 in the wild.