CVE-2013-4372: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3 allow remote attackers to inject arbitrary web script or HTML via the (1) user field in the create user page or (2) profile version to the create profile page.
Other sources
Multiple stored cross-site scripting (XSS) flaws were found in the Fuse Management Console. A remote attacker could use this flaw to perform an XSS attack against other users of the Fuse Management Console.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4372?
CVE-2013-4372 has a medium severity level due to its potential for remote exploitation through cross-site scripting (XSS).
How do I fix CVE-2013-4372?
To fix CVE-2013-4372, apply the latest patches provided for Red Hat JBoss Fuse and JBoss A-MQ version 6.0.0.
What applications are affected by CVE-2013-4372?
CVE-2013-4372 affects Red Hat JBoss Fuse 6.0.0 before patch 3 and JBoss A-MQ 6.0.0 before patch 3.
What is a cross-site scripting (XSS) vulnerability in the context of CVE-2013-4372?
In the context of CVE-2013-4372, an XSS vulnerability allows attackers to inject malicious web scripts or HTML into the application, potentially compromising users' security.
Can CVE-2013-4372 be exploited without authentication?
Yes, CVE-2013-4372 can be exploited by remote attackers, which means that authentication may not be required for the attack.