1 results (0.003 seconds)

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

29 Nov 2016 — JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business processes can store scripts in them, which are not properly sanitized before showing to other users, including admins. JBoss BRMS 6 y BPM Suite 6 son vulnerables a Cross-Site Scripting (XSS) persistente mediante el editor de procesos de negocio. Este error existe debido a una solución incomplet... • http://rhn.redhat.com/errata/RHSA-2016-2822.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •