CVE-2013-6465
published 2017-12-19CVE-2013-6465: Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via…
PriorityP421medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.06%
60.7th percentile
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jbpm | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g34w-4mj2-gjww: Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6
ghsa_unreviewed·2022-05-14
CVE-2013-6465 [MEDIUM] CWE-79 GHSA-g34w-4mj2-gjww: Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
Red Hat
Workbench: Multiple stored XSS issues
vendor_redhat·2014-02-06·CVSS 5.4
CVE-2013-6465 [MEDIUM] CWE-79 Workbench: Multiple stored XSS issues
Workbench: Multiple stored XSS issues
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
Statement: This issue does not affect jBPM KIE Workbench as shipped with Red Hat JBoss BPM Suite 6.0.0. It may affect earlier versions of the upstream jBPM Console NG project.
Package: Workbench (Red Hat JBoss BRMS 5) - Not affected
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1048380https://github.com/kiegroup/jbpm-wb/commit/4818204506e8e94645b52adb9426bedfa9ffdd04https://github.com/kiegroup/jbpm-wb/compare/6.0.xhttps://bugzilla.redhat.com/show_bug.cgi?id=1048380https://github.com/kiegroup/jbpm-wb/commit/4818204506e8e94645b52adb9426bedfa9ffdd04https://github.com/kiegroup/jbpm-wb/compare/6.0.x
2017-12-19
Published