Description
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1968.html
http://rhn.redhat.com/errata/RHSA-2016-1969.html
http://www.securityfocus.com/bid/93219
https://bugzilla.redhat.com/show_bug.cgi?id=1358523
Related Vulnerabilities
CVE-2021-32685 Vulnerability in npm package tenvoy
CVE-2021-32702 Vulnerability in npm package nextjs-auth0
CVE-2022-23621 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2021-40143 Vulnerability in maven package org.sonatype.nexus:nexus-repository
CVE-2023-50723 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui