3.5
CVSSv2

CVE-2013-0177

Published: 30/01/2014 Updated: 18/05/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x prior to 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.

Vulnerable Product Search on Vulmon Subscribe to Product

apache ofbiz 09.04.01

apache ofbiz 10.04.01

apache ofbiz 10.04.03

apache ofbiz 10.04.04

apache ofbiz 11.04.01

apache ofbiz 09.04

apache ofbiz 10.04

apache ofbiz 10.04.02

Exploits

source: wwwsecurityfocuscom/bid/57463/info Apache OFBiz is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site This may l ...
Apache OFBiz versions 100405 and below and 110401 and below suffer from a reflected cross site scripting vulnerability Full exploitation details provided ...