PT-2014-6230 · Telerik · Telerik Ui For Asp.Net Ajax Radeditor

Published

2014-09-26

·

Updated

2015-09-16

·

CVE-2014-4958

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Telerik UI for ASP.NET AJAX RadEditor control versions 2009.3.1208.20 through 2014.1.403.35
Description The issue is related to a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.
Recommendations For versions 2009.3.1208.20 through 2014.1.403.35, consider disabling the RadEditor control until a patch is available to prevent exploitation. Restrict access to the control to minimize the risk of XSS attacks. Avoid using CSS expressions in style attributes in the affected RadEditor control until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4958

Affected Products

Telerik Ui For Asp.Net Ajax Radeditor