Vulnerabilities (CVE)

Filtered by vendor Eng Subscribe
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-6233 1 Eng 1 Spagobi 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."
CVE-2013-6232 1 Eng 1 Spagobi 2024-02-04 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.
CVE-2014-7296 1 Eng 1 Spagobi 2024-02-04 6.8 MEDIUM N/A
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.