PT-2014-6230 · Telerik · Telerik Ui For Asp.Net Ajax Radeditor

Publicado

2014-09-26

·

Atualizado

2015-09-16

·

CVE-2014-4958

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Telerik UI for ASP.NET AJAX RadEditor control versions 2009.3.1208.20 through 2014.1.403.35
Description The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.
Recommendations For versions 2009.3.1208.20 through 2014.1.403.35, consider disabling the RadEditor control until a patch is available to prevent exploitation. Restrict access to the control to minimize the risk of XSS attacks. Avoid using CSS expressions in style attributes in the affected RadEditor control until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-4958

Produtos afetados

Telerik Ui For Asp.Net Ajax Radeditor