{"id":"CVE-2013-1879","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-1879","summary":"Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ","details":"Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the \"cron of a message.\"","published":"2022-05-17T01:36:25Z","modified":"2024-12-07T05:38:26.754799Z","cvss":null,"epss":{"score":0.06593,"percentile":0.93315,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.activemq:activemq-client","fixedVersion":"5.9.0"}],"fix":{"url":"https://github.com/apache/activemq/commit/148ca81dcd8f14cfe2ff37012fd1aa42518f02dc","label":"apache/activemq@148ca81"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1879"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/148ca81dcd8f14cfe2ff37012fd1aa42518f02dc"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/85586"},{"type":"WEB","url":"https://github.com/apache/activemq"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/AMQ-4397"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2013-1029.html"},{"type":"WEB","url":"http://secunia.com/advisories/54073"},{"type":"WEB","url":"http://www.securityfocus.com/bid/61142"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-07T05:38:26.754799Z"}}