VYPR

Spagobi

by Eng

CVEs (3)

  • CVE-2013-6233Mar 9, 2014
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."

  • CVE-2013-6232Mar 9, 2014
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.

  • CVE-2014-7296Oct 8, 2014
    risk 0.00cvss epss 0.01

    The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.