MEDIUM
cumin: non-persistent XSS possible due to not escaping set limit form input
Published Dec 23, 2013
4.3
MEDIUMCVSS 2.0
EPSS 1.80%
Description
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
Affected products
No data.
- 2.4
No data.
MRG for RHEL-5 v. 2
cumin-0:0.1.5787-4.el5
Fixed · RHSA-2013:1851
Red Hat Enterprise MRG 2
cumin-0:0.1.5787-4.el6
Fixed · RHSA-2013:1852
Red Hat Enterprise MRG 2
rubygems-0:1.8.23.2-1.el6
Fixed · RHSA-2013:1852
| Product | Package | State | Advisory |
|---|---|---|---|
| MRG for RHEL-5 v. 2 | cumin-0:0.1.5787-4.el5 | Fixed | RHSA-2013:1851 |
| Red Hat Enterprise MRG 2 | cumin-0:0.1.5787-4.el6 | Fixed | RHSA-2013:1852 |
| Red Hat Enterprise MRG 2 | rubygems-0:1.8.23.2-1.el6 | Fixed | RHSA-2013:1852 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=998606 x_refsource_CONFIRM
- http://rhn.redhat.com/errata/RHSA-2013-1851.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1852.html vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2013-4414 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=998606 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4291 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4414
- https://www.cve.org/CVERecord?id=CVE-2013-4414
| Link | Providers | Tags |
|---|---|---|
| http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=998606 | x_refsource_CONFIRM | |
| http://rhn.redhat.com/errata/RHSA-2013-1851.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| http://rhn.redhat.com/errata/RHSA-2013-1852.html | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2013-4414 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=998606 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-4291 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4414 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-4414 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 23, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4414
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-4291 Assigner redhat
Published Dec 23, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-4291