cbcvebase.
CVE-2013-2137
published 2013-08-15

CVE-2013-2137: Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through…

PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
7.70%
93.9th percentile
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected

9 ranges
VendorProductVersion rangeFixed in
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz
apacheofbiz

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_apache4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.