CVE-2014-0341

UnknownEPSS 1.89%

Last modified

CVE-2014-0341 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_internal/entries.tpl; (4) an event field to objects.php; or the (5) email or (6) nickname field to pages.php, related to templates_internal/users.tpl.. EPSS estimates a 1.89% chance of exploitation in the next 30 days.

Description

Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_internal/entries.tpl; (4) an event field to objects.php; or the (5) email or (6) nickname field to pages.php, related to templates_internal/users.tpl.

Metrics

EPSS Probability
1.89%

76.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PivotxPivotx<= 2.3.8
PivotxPivotx2.1.0
PivotxPivotx2.1.1
PivotxPivotx2.1.2
PivotxPivotx2.2.0
PivotxPivotx2.2.1
PivotxPivotx2.2.2
PivotxPivotx2.2.3
PivotxPivotx2.2.5
PivotxPivotx2.3.0
PivotxPivotx2.3.2
PivotxPivotx2.3.3
PivotxPivotx2.3.5
PivotxPivotx2.3.6
PivotxPivotx2.3.7

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-0341?
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_internal/entries.tpl; (4) an event field to objects.php; or the (5) email or (6) nickname field to pages.php, related to templates_internal/users.tpl.
How severe is CVE-2014-0341?
Severity scoring for CVE-2014-0341 is pending analysis. The EPSS model estimates a 1.89% probability of exploitation in the next 30 days.
How do I fix CVE-2014-0341?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-0341?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST