First published: Wed Jun 18 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified report parameters.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Web Gateway | <=5.1.1 | |
Symantec Web Gateway | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1652 is rated as a medium severity vulnerability due to its potential for exploitation by remote authenticated users.
To fix CVE-2014-1652, upgrade to Symantec Web Gateway version 5.2 or later.
CVE-2014-1652 affects users of Symantec Web Gateway versions prior to 5.2, particularly those using the management console.
CVE-2014-1652 is associated with multiple cross-site scripting (XSS) vulnerabilities within the management console.
Using an affected version of Symantec Web Gateway poses a security risk, and it is recommended to update to a patched version.