4.3
CVSSv2

CVE-2013-6233

Published: 09/03/2014 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in SpagoBI prior to 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."

Vulnerable Product Search on Vulmon Subscribe to Product

eng spagobi

Exploits

################################################### 01 ### Advisory Information ### Title: Persistent HTML Script Insertion permits offsite-bound forms Date published: 2014-03-01 Date of last update: 2014-03-01 Vendors contacted: Engineering Group Discovered by: Christian Catalano Severity: Medium 02 ### Vulnerability Information ### CVE r ...
SpagoBI version 40 suffers from an HTML injection vulnerability ...