CVE-2013-4378
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
30/09/2013
Last modified:
11/04/2025
Description
Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:emeric_vernat:javamelody:*:*:*:*:*:*:*:* | 1.46 (including) | |
cpe:2.3:a:emeric_vernat:javamelody:1.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.9:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.11:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.13:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.14:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.15:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.16:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.17:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.18:*:*:*:*:*:*:* | ||
cpe:2.3:a:emeric_vernat:javamelody:1.19:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/97778
- http://seclists.org/oss-sec/2013/q3/679
- http://www.securityfocus.com/bid/62679
- https://code.google.com/p/javamelody/issues/detail?id=346
- https://code.google.com/p/javamelody/source/detail?r=3515
- https://code.google.com/p/javamelody/wiki/ReleaseNotes
- http://osvdb.org/97778
- http://seclists.org/oss-sec/2013/q3/679
- http://www.securityfocus.com/bid/62679
- https://code.google.com/p/javamelody/issues/detail?id=346
- https://code.google.com/p/javamelody/source/detail?r=3515
- https://code.google.com/p/javamelody/wiki/ReleaseNotes