CVE-2013-4414
published 2013-12-23CVE-2013-4414: Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.80%
76.1th percentile
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wrxh-jqj9-66hp: Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2
ghsa_unreviewed·2022-05-13
CVE-2013-4414 [MEDIUM] CWE-79 GHSA-wrxh-jqj9-66hp: Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
Red Hat
cumin: non-persistent XSS possible due to not escaping set limit form input
vendor_redhat·2013-12-17·CVSS 4.3
CVE-2013-4414 [MEDIUM] CWE-79 cumin: non-persistent XSS possible due to not escaping set limit form input
cumin: non-persistent XSS possible due to not escaping set limit form input
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
No detection rules found.
No public exploits indexed.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=998606http://rhn.redhat.com/errata/RHSA-2013-1851.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1852.htmlhttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=998606http://rhn.redhat.com/errata/RHSA-2013-1851.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1852.html
2013-12-23
Published