Unrated severityNVD Advisory· Published Jan 30, 2014· Updated Apr 29, 2026
CVE-2013-0177
CVE-2013-0177
Description
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.
Affected products
8cpe:2.3:a:apache:ofbiz:09.04:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:apache:ofbiz:09.04:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ofbiz:09.04.01:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ofbiz:10.04:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ofbiz:10.04.01:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ofbiz:10.04.02:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ofbiz:10.04.03:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ofbiz:10.04.04:*:*:*:*:*:*:*
- cpe:2.3:a:apache:ofbiz:11.04.01:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- ofbiz.apache.org/download.htmlnvdVendor Advisory
- packetstormsecurity.com/files/119673/Apache-OFBiz-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2013/Jan/148nvdMailing ListThird Party Advisory
- secunia.com/advisories/51812nvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/81398nvdThird Party AdvisoryVDB Entry
- osvdb.org/89452nvdBroken Link
- osvdb.org/89453nvdBroken Link
- fisheye6.atlassian.com/changelog/ofbiznvdBroken Link
- fisheye6.atlassian.com/changelog/ofbiznvdBroken Link
News mentions
0No linked articles in our index yet.