PT-2014-4590 · Eugene Pankov · Ajenti

Published

2014-04-30

·

Updated

2022-05-17

·

CVE-2014-2260

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Ajenti versions 1.2.13 through 1.2.14 Ajenti version 1.2.15 is not affected, so versions prior to 1.2.15 are vulnerable. However, since 1.2.13 is the lowest version mentioned as vulnerable, the range can be simplified to: Ajenti versions 1.2.13 through 1.2.14
Description The issue is a cross-site scripting (XSS) vulnerability in the plugins/main/content/js/ajenti.coffee file. This allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
Recommendations For Ajenti versions 1.2.13 through 1.2.14, update to version 1.2.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the Cron functionality to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2260
GHSA-9CRX-P357-5VW8
PYSEC-2014-98

Affected Products

Ajenti