First published: Tue Jan 13 2015(Updated: )
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JetBrains TeamCity | <=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-10036 has a medium severity rating due to its potential for cross-site scripting exploitation.
To fix CVE-2014-10036, upgrade JetBrains TeamCity to version 8.1 or later.
CVE-2014-10036 affects JetBrains TeamCity versions prior to 8.1.
Yes, CVE-2014-10036 can be exploited remotely by sending a malicious request to the affected application.
CVE-2014-10036 is a cross-site scripting (XSS) vulnerability that allows for arbitrary web script injection.