CVE-2013-6465: XSS
Gregory Draperi reports:
A cross-site scripting flaw has been reported in jBPM. The flaw allows remote authenticated attackers to store arbitrary script code in certain jBPM workbench fields, the script could be executed later in the context of other users while browsing through several workbench pages.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6465?
CVE-2013-6465 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-6465?
To fix CVE-2013-6465, update to a version of jBPM that addresses the cross-site scripting vulnerability.
Which versions of jBPM are affected by CVE-2013-6465?
CVE-2013-6465 affects jBPM versions 6.0.0 including alpha, beta, and release candidates up to cr5.
Can CVE-2013-6465 be exploited by unauthenticated users?
No, CVE-2013-6465 requires remote authenticated attackers to exploit the vulnerability.
What type of vulnerability is CVE-2013-6465?
CVE-2013-6465 is a cross-site scripting (XSS) vulnerability that allows the storage of arbitrary script code.