CVE-2013-4204

Severity
4.3MEDIUM
EPSS
0.2%
top 53.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 18
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 2.5.1 RC1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDgoogle/web_toolkit2.5.0+23
Mavencom.google.gwt:gwt< 2.5.1

Patches

🔴Vulnerability Details

3
GHSA
Improper Neutralization of Input During Web Page Generation in Google Web Toolkit2022-05-17
OSV
Improper Neutralization of Input During Web Page Generation in Google Web Toolkit2022-05-17
CVEList
CVE-2013-4204: Multiple cross-site scripting (XSS) vulnerabilities in the JUnit files in the GWTTestCase in Google Web Toolkit (GWT) before 22013-11-15

📋Vendor Advisories

1
Red Hat
GWT: reflected XSS in HTML files used by GWTTestCase2013-02-14

💬Community

1
Bugzilla
CVE-2013-4204 GWT: reflected XSS in HTML files used by GWTTestCase2013-08-05