CVE-2013-6175: XSS
Multiple cross-site scripting (XSS) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote attackers to inject arbitrary web script or HTML via unspecified input to a (1) xAdmin or (2) xDashboard form.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EMC Document Sciences xPressionto a version that resolves this vulnerability.Patch Patch 47 - Upgrade
Upgrade
EMC Document Sciences xPressionto a version that resolves this vulnerability.Fixed in 4.2Patch Patch 26 - Upgrade
Upgrade
EMC Document Sciences xPressionto a version that resolves this vulnerability.Fixed in 4.5Patch Patch 05
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6175?
CVE-2013-6175 is classified as a medium severity vulnerability due to its potential impact from cross-site scripting attacks.
How do I fix CVE-2013-6175?
To address CVE-2013-6175, it is recommended to apply the appropriate patches: Patch 47 for version 4.1 SP1, Patch 26 for version 4.2, and Patch 05 for version 4.5.
Which software is affected by CVE-2013-6175?
CVE-2013-6175 affects EMC Document Sciences xPression versions 4.1 SP1, 4.2, and 4.5.
What type of vulnerability is CVE-2013-6175?
CVE-2013-6175 is a cross-site scripting (XSS) vulnerability that can allow remote attackers to inject arbitrary web script or HTML.
When was CVE-2013-6175 reported?
CVE-2013-6175 was reported in November 2013.