PT-2014-4590 · Eugene Pankov · Ajenti
Published
2014-04-30
·
Updated
2022-05-17
·
CVE-2014-2260
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Ajenti versions 1.2.13 through 1.2.14
Ajenti version 1.2.15 is not affected, so versions prior to 1.2.15 are vulnerable. However, since 1.2.13 is the lowest version mentioned as vulnerable, the range can be simplified to:
Ajenti versions 1.2.13 through 1.2.14
Description
The issue is a cross-site scripting (XSS) vulnerability in the
plugins/main/content/js/ajenti.coffee file. This allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.Recommendations
For Ajenti versions 1.2.13 through 1.2.14, update to version 1.2.15 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Cron functionality to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ajenti