CVE-2013-0177
Summary
| CVE | CVE-2013-0177 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-30 15:06:22 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages. |
Risk And Classification
Primary CVSS: v2.0 3.5 from [email protected]
AV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS: 0.042100000 probability, percentile 0.887840000 (date 2026-05-04)
Problem Types: CWE-79 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Ofbiz | 09.04 | All | All | All |
| Application | Apache | Ofbiz | 09.04.01 | All | All | All |
| Application | Apache | Ofbiz | 10.04 | All | All | All |
| Application | Apache | Ofbiz | 10.04.01 | All | All | All |
| Application | Apache | Ofbiz | 10.04.02 | All | All | All |
| Application | Apache | Ofbiz | 10.04.03 | All | All | All |
| Application | Apache | Ofbiz | 10.04.04 | All | All | All |
| Application | Apache | Ofbiz | 11.04.01 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: [CVE-2013-0177] Cross-Site Scripting (XSS) Vulnerability in Apache OFBiz | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Third Party Advisory |
| osvdb.org/89453 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| fisheye6.atlassian.com/changelog/ofbiz | af854a3a-2127-422b-91ae-364da2661108 | fisheye6.atlassian.com | Broken Link |
| Apache OFBiz Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| osvdb.org/89452 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Apache OFBiz - Download Releases | af854a3a-2127-422b-91ae-364da2661108 | ofbiz.apache.org | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Security Advisory SA51812 - Apache OFBiz Two Cross-Site Scripting Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| fisheye6.atlassian.com/changelog/ofbiz | af854a3a-2127-422b-91ae-364da2661108 | fisheye6.atlassian.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.