PT-2023-10104 · Unknown · Stiiv Contact App

Published

2023-01-02

·

Updated

2024-05-17

·

CVE-2014-125034

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions stiiv contact app (affected versions not specified)
Description A vulnerability has been found in stiiv contact app and classified as problematic. The function render of the file libs/View.php is affected by this issue. The manipulation of the argument var leads to cross site scripting. The attack can be launched remotely.
Recommendations To fix this issue, it is recommended to apply a patch named 67bec33f559da9d41a1b45eb9e992bd8683a7f8c. As a temporary workaround, consider disabling the render function of the libs/View.php file until the patch is applied. Restrict access to the var argument to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2014-125034

Affected Products

Stiiv Contact App