CVE-2014-10036: XSS
Published Jan 13, 2015
·Updated
Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/generateFeedUrl.html.
Affected Software
1 affected component
JetBrains TeamCity<=8.0
Event History
Jan 13, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-10036?
CVE-2014-10036 has a medium severity rating due to its potential for cross-site scripting exploitation.
2
How do I fix CVE-2014-10036?
To fix CVE-2014-10036, upgrade JetBrains TeamCity to version 8.1 or later.
3
What systems are affected by CVE-2014-10036?
CVE-2014-10036 affects JetBrains TeamCity versions prior to 8.1.
4
Can CVE-2014-10036 be exploited remotely?
Yes, CVE-2014-10036 can be exploited remotely by sending a malicious request to the affected application.
5
What is the nature of the vulnerability in CVE-2014-10036?
CVE-2014-10036 is a cross-site scripting (XSS) vulnerability that allows for arbitrary web script injection.