CVE-2014-1648: XSS
Published Apr 23, 2014
·Updated
Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.
Affected Software
6 affected components
Symantec Messaging Gateway=10.0
Symantec Messaging Gateway=10.0.1
Symantec Messaging Gateway=10.0.2
Symantec Messaging Gateway=10.0.3
Symantec Messaging Gateway=10.5.0
Symantec Messaging Gateway=10.5.1
Event History
Apr 23, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·11:52 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1648?
CVE-2014-1648 is classified as a critical cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-1648?
To fix CVE-2014-1648, upgrade Symantec Messaging Gateway to version 10.5.2 or later.
3
What systems are affected by CVE-2014-1648?
CVE-2014-1648 affects Symantec Messaging Gateway versions 10.0 through 10.5.1.
4
Can CVE-2014-1648 be exploited remotely?
Yes, CVE-2014-1648 can be exploited remotely by attackers to inject arbitrary web scripts.
5
What impact does CVE-2014-1648 have on affected systems?
CVE-2014-1648 allows attackers to execute scripts in the context of the user's session, potentially leading to data theft or session hijacking.