CVE-2013-1879Cross-site Scripting in Apache Activemq

Severity
4.3MEDIUMNVD
EPSS
5.5%
top 9.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 20
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapache/activemq5.8.0+13

🔴Vulnerability Details

3
OSV
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ2022-05-17
GHSA
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ2022-05-17
CVEList
CVE-2013-1879: Cross-site scripting (XSS) vulnerability in scheduled2013-07-18

📋Vendor Advisories

2
Red Hat
ActiveMQ: XSS vulnerability in scheduled.jsp2013-03-21
Debian
CVE-2013-1879: activemq - Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8...2013

💬Community

2
Bugzilla
CVE-2013-1879 CVE-2013-1880 activemq various flaws [fedora-18]2013-03-21
Bugzilla
CVE-2013-1879 ActiveMQ: XSS vulnerability in scheduled.jsp2013-03-21
CVE-2013-1879 — Cross-site Scripting in Apache Activemq | cvebase