Spagobi
by Eng
CVEs (3)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2013-6233 | 0.03 | — | 0.05 | Mar 9, 2014 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata." | ||
| CVE-2013-6232 | 0.03 | — | 0.01 | Mar 9, 2014 | Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page. | ||
| CVE-2014-7296 | 0.00 | — | 0.01 | Oct 8, 2014 | The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document. |
- CVE-2013-6233Mar 9, 2014risk 0.03cvss —epss 0.05
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."
- CVE-2013-6232Mar 9, 2014risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.
- CVE-2014-7296Oct 8, 2014risk 0.00cvss —epss 0.01
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.