PT-2014-6230 · Telerik · Telerik Ui For Asp.Net Ajax Radeditor
Published
2014-09-26
·
Updated
2015-09-16
·
CVE-2014-4958
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Telerik UI for ASP.NET AJAX RadEditor control versions 2009.3.1208.20 through 2014.1.403.35
Description
The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.
Recommendations
For versions 2009.3.1208.20 through 2014.1.403.35, consider disabling the RadEditor control until a patch is available to prevent exploitation.
Restrict access to the control to minimize the risk of XSS attacks.
Avoid using CSS expressions in style attributes in the affected RadEditor control until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telerik Ui For Asp.Net Ajax Radeditor