CVE-2013-6465

MEDIUM

JBPM KIE Workbench 6.0.x - Authenticated Cross-Site Scripting via Task Name HTML Input

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-6465. PoCs published by dawetmaster, andikahilmy.

AI-analyzed exploit summary This repository contains source code for jBPM Console NG, specifically the asset management module, which is vulnerable to CVE-2013-6465. The code includes interfaces and implementations for repository configuration, project building, and asset promotion, but does not include an exploit PoC or detailed vulnerability analysis.

Description

Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.

Exploits (2)

nomisec WRITEUP
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2013-6465-jjbpm-wbbpm-vulnerable

This repository contains source code for jBPM Console NG, specifically the asset management module, which is vulnerable to CVE-2013-6465. The code includes interfaces and implementations for repository configuration, project building, and asset promotion, but does not include an exploit PoC or detailed vulnerability analysis.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: jBPM Console NG (version not specified)
Auth required
Prerequisites: access to vulnerable jBPM Console NG instance · valid credentials for authenticated endpoints
devstral-2 · analyzed Mar 14, 2026 Full analysis →
nomisec WRITEUP
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2013-6465-jjbpm-wbbpm-vulnerable

This repository contains source code for jBPM Console NG, specifically the asset management module, which is vulnerable to CVE-2013-6465. The code includes interfaces and implementations for repository configuration, project building, and asset promotion, but does not include an exploit PoC or detailed vulnerability analysis.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: jBPM Console NG (version not specified)
Auth required
Prerequisites: Access to vulnerable jBPM Console NG instance · Valid credentials for authenticated endpoints
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 5.4
EPSS 0.0106
EPSS Percentile 59.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
redhat/jbpm 6.0.0 (13 CPE variants)
Published Dec 19, 2017
Tracked Since Feb 18, 2026