CVE-2013-6465

Severity
5.4MEDIUM
EPSS
0.2%
top 63.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19
Latest updateMay 14

Description

Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

NVDredhat/jbpm6.0.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g34w-4mj2-gjww: Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 62022-05-14
CVEList
CVE-2013-6465: Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 62017-12-19

📋Vendor Advisories

1
Red Hat
Workbench: Multiple stored XSS issues2014-02-06

💬Community

1
Bugzilla
CVE-2013-6465 JBPM KIE Workbench: Multiple stored XSS issues2014-01-03
CVE-2013-6465 (MEDIUM CVSS 5.4) | Multiple cross-site scripting (XSS) | cvebase.io