CVE-2013-6232: XSS
Published Mar 7, 2014
·Updated
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.
Affected Software
1 affected component
eng SpagoBI<=4.0
Event History
Mar 7, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Mar 9, 2014
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6232?
The severity of CVE-2013-6232 is classified as medium due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2013-6232?
To fix CVE-2013-6232, upgrade to SpagoBI version 4.1 or later where the vulnerability is patched.
3
Who is affected by CVE-2013-6232?
CVE-2013-6232 affects remote authenticated users of SpagoBI versions before 4.1.
4
What kind of attacks can CVE-2013-6232 facilitate?
CVE-2013-6232 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
5
Is user authentication required to exploit CVE-2013-6232?
Yes, exploiting CVE-2013-6232 requires user authentication as it targets authenticated users.