cvedb.io
CVE-2017-2674
MEDIUM · CVSS 6.1
EPSS exploitation probability: 0%
Published 2018-07-27T18:29:01.237 · Last modified 2026-06-17T01:16:38.250

Summary

JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.

Affected products

redhat — jboss_bpm_suite

Does this affect you?

Add your gear to cvedb and we'll alert you only when redhat ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.