CVE-2013-5300
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or…
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via the withoutmenu parameter to (1) vulnmeter/index.php or (2) vulnmeter/sched.php; the (3) section parameter to av_inventory/task_edit.php; the (4) profile parameter to nfsen/rrdgraph.php; or the (5) scan_server or (6) targets parameter to vulnmeter/simulate.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- alienvault/open source security information management
- Source
- cve@mitre.org
References
- http://forums.alienvault.com/discussion/1609/patch-release-4-3-1
- http://packetstormsecurity.com/files/122547/Alienvault-OSSIM-Cross-Site-Scripting.html
- http://secunia.com/advisories/54264Vendor Advisory
- http://secunia.com/advisories/54287Vendor Advisory
- http://www.osvdb.org/show/osvdb/95813
- http://www.osvdb.org/show/osvdb/95814
- http://www.osvdb.org/show/osvdb/95816
- http://www.osvdb.org/show/osvdb/95817
- http://www.osvdb.org/show/osvdb/95818
- http://www.securityfocus.com/bid/61456
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85994
- http://forums.alienvault.com/discussion/1609/patch-release-4-3-1
- http://packetstormsecurity.com/files/122547/Alienvault-OSSIM-Cross-Site-Scripting.html
- http://secunia.com/advisories/54264Vendor Advisory
- http://secunia.com/advisories/54287Vendor Advisory
- http://www.osvdb.org/show/osvdb/95813
- http://www.osvdb.org/show/osvdb/95814
- http://www.osvdb.org/show/osvdb/95816
- http://www.osvdb.org/show/osvdb/95817
- http://www.osvdb.org/show/osvdb/95818
- http://www.securityfocus.com/bid/61456
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85994
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.