CVE-2009-4521

Eclipse BIRT <2.5.0 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michele Orru · textwebappsjava
https://www.exploit-db.com/exploits/33286

Scores

EPSS 0.0371
EPSS Percentile 87.8%

Classification

CWE
CWE-79
Status published

Affected Products (2)

eclipse/birt < 2.3.2
n/a/n/a

Timeline

Published Dec 31, 2009
Tracked Since Feb 18, 2026