First published: Sat Oct 19 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware before 11.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Fireware OS | <=11.7.4 | |
WatchGuard Fireware OS | =11.6 | |
WatchGuard Fireware OS | =11.6.1 | |
WatchGuard Fireware OS | =11.6.3 | |
WatchGuard Fireware OS | =11.6.5 | |
WatchGuard Fireware OS | =11.6.6 | |
WatchGuard Fireware OS | =11.7 | |
WatchGuard Fireware OS | =11.7.2 | |
WatchGuard Fireware OS | =11.7.3 | |
Watchguard Watchguard System Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5702 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2013-5702, upgrade the WatchGuard Fireware to version 11.8 or later.
CVE-2013-5702 affects WatchGuard Fireware versions prior to 11.8, including versions 11.6 up to 11.7.4.
Yes, CVE-2013-5702 can be exploited remotely by attackers who can inject arbitrary web scripts or HTML.
CVE-2013-5702 allows attackers to execute malicious scripts in the context of the user’s browser, posing risks to user data.