CVE-2013-6233

ENG Spagobi < 4.0 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."

Exploits (1)

exploitdb WRITEUP
by Christian Catalano · textwebappsphp
https://www.exploit-db.com/exploits/32039

Scores

EPSS 0.0486
EPSS Percentile 89.5%

Details

CWE
CWE-79
Status published
Products (2)
eng/spagobi < 4.0
n/a/n/a
Published Mar 09, 2014
Tracked Since Feb 18, 2026