CVE-2016-6343

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
31/10/2018
Last modified:
12/02/2023

Description

JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that have privileges to access dashbuilder (usually admins) to click on links to /dashbuilder/Controller containing malicious scripts. Successful exploitation would allow execution of script code within the context of the affected user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:jboss_bpm_suite:*:*:*:*:*:*:*:* 6.0.0 (including) 6.4.2 (excluding)