CVE-2013-6233: XSS
Published Mar 7, 2014
·Updated
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."
Affected Software
1 affected component
eng SpagoBI<=4.0
Event History
Mar 7, 2014
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Mar 9, 2014
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6233?
The severity of CVE-2013-6233 is classified as medium due to its ability to allow authenticated users to exploit cross-site scripting vulnerabilities.
2
How do I fix CVE-2013-6233?
To fix CVE-2013-6233, you should upgrade SpagoBI to version 4.1 or later, which addresses this vulnerability.
3
Who is affected by CVE-2013-6233?
CVE-2013-6233 affects remote authenticated users of SpagoBI versions prior to 4.1.
4
What kind of attack does CVE-2013-6233 enable?
CVE-2013-6233 enables attackers to inject arbitrary web scripts or HTML into the Description field of the Short document metadata.
5
Can CVE-2013-6233 be exploited without authentication?
No, CVE-2013-6233 can only be exploited by remote authenticated users.