4.3
CVE-2014-4853
- EPSS 1.94%
- Veröffentlicht 10.07.2014 16:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opendocman ≫ Opendocman Version <= 1.2.7.2
Opendocman ≫ Opendocman Version1.2.6.2 Update-
Opendocman ≫ Opendocman Version1.2.6.2 Updatea
Opendocman ≫ Opendocman Version1.2.6.2 Updateb
Opendocman ≫ Opendocman Version1.2.6.3 Update-
Opendocman ≫ Opendocman Version1.2.6.3 Updatea
Opendocman ≫ Opendocman Version1.2.6.5
Opendocman ≫ Opendocman Version1.2.6.6
Opendocman ≫ Opendocman Version1.2.6.7 Update-
Opendocman ≫ Opendocman Version1.2.6.7 Updatebeta
Opendocman ≫ Opendocman Version1.2.6.8
Opendocman ≫ Opendocman Version1.2.7
Opendocman ≫ Opendocman Version1.2.7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.94% | 0.775 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://packetstormsecurity.com/files/127330/OpenDocMan-1.2.7.2-Cross-Site-Scripting.html
http://www.opendocman.com/opendocman-v1-2-7-3-release-notes
https://github.com/opendocman/opendocman/commit/d202ef3def8674be61a3e4ccbe28beba4953b7ce
https://github.com/opendocman/opendocman/issues/163