PT-2014-4590 · Eugene Pankov · Ajenti

Publicado

2014-04-30

·

Atualizado

2022-05-17

·

CVE-2014-2260

CVSS v4.0

5.1

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Ajenti versions 1.2.13 through 1.2.14 Ajenti version 1.2.15 is not affected, so versions prior to 1.2.15 are vulnerable. However, since 1.2.13 is the lowest version mentioned as vulnerable, the range can be simplified to: Ajenti versions 1.2.13 through 1.2.14
Description The issue is a cross-site scripting (XSS) vulnerability in the plugins/main/content/js/ajenti.coffee file. This allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
Recommendations For Ajenti versions 1.2.13 through 1.2.14, update to version 1.2.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the Cron functionality to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2260
GHSA-9CRX-P357-5VW8
PYSEC-2014-98

Produtos afetados

Ajenti