PT-2014-6230 · Telerik · Telerik Ui For Asp.Net Ajax Radeditor
Publicado
2014-09-26
·
Atualizado
2015-09-16
·
CVE-2014-4958
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Telerik UI for ASP.NET AJAX RadEditor control versions 2009.3.1208.20 through 2014.1.403.35
Description
The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.
Recommendations
For versions 2009.3.1208.20 through 2014.1.403.35, consider disabling the RadEditor control until a patch is available to prevent exploitation.
Restrict access to the control to minimize the risk of XSS attacks.
Avoid using CSS expressions in style attributes in the affected RadEditor control until the issue is resolved.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Telerik Ui For Asp.Net Ajax Radeditor