CVE-2014-0793: XSS
Published Jan 30, 2014
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (comkomento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website or (2) latitude parameter in a comment to the default URI.
Affected Software
8 affected components
StackIdeas Komento<=1.7.2
StackIdeas Komento=1.7.0
StackIdeas Komento=1.7.1
Joomla Joomla\!
All of the following
Any of the following
StackIdeas Komento<=1.7.2
StackIdeas Komento=1.7.0
StackIdeas Komento=1.7.1
Joomla Joomla\!
Event History
Jan 30, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0793?
CVE-2014-0793 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-0793?
To fix CVE-2014-0793, update the Komento component to version 1.7.3 or later.
3
What versions of Komento are affected by CVE-2014-0793?
CVE-2014-0793 affects Komento versions 1.7.0, 1.7.1, and up to 1.7.2.
4
What type of vulnerability is CVE-2014-0793?
CVE-2014-0793 is a multiple cross-site scripting (XSS) vulnerability.
5
Can CVE-2014-0793 be exploited remotely?
Yes, CVE-2014-0793 can be exploited remotely, allowing attackers to inject arbitrary web script or HTML.