01642 06 11 11 Arrange Call

Cross-Site Scripting (XSS) Vulnerabilities in Apache OFBiz Widget/Screen/ModelScreenWidget.java

CVE-2013-0177 · LOW

CVE-2013-0177

Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.

Learn more about our Cis Benchmark Audit For Apache Http Server.