CVE-2013-2137
published 2013-08-15CVE-2013-2137: Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
7.70%
93.9th percentile
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_apache4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x8qj-3m3j-c84j: Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10
ghsa_unreviewed·2022-05-14
CVE-2013-2137 [MEDIUM] CWE-79 GHSA-x8qj-3m3j-c84j: Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Apache
Apache ofbiz: CVE-2013-2137
vendor_apache·CVSS 4.3
CVE-2013-2137 [MEDIUM] Apache ofbiz: CVE-2013-2137
Apache ofbiz: CVE-2013-2137
; affected releases: 12.04.01, 11.04.02 and earlier versions (11.04.*), 10.04.05 and earlier versions (10.04.*); fixed in 12.04.02, 11.04.03 and 10.04.06
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2013-07/0144.htmlhttp://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/95523http://secunia.com/advisories/53910http://www.securityfocus.com/bid/61370https://exchange.xforce.ibmcloud.com/vulnerabilities/85874http://archives.neohapsis.com/archives/bugtraq/2013-07/0144.htmlhttp://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/95523http://secunia.com/advisories/53910http://www.securityfocus.com/bid/61370https://exchange.xforce.ibmcloud.com/vulnerabilities/85874
2013-08-15
Published