CVE-2014-1837: XSS
Published Jan 30, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (comkomento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."
Affected Software
4 affected components
StackIdeas Komento<=1.7.3
StackIdeas Komento=1.7.0
StackIdeas Komento=1.7.1
StackIdeas Komento=1.7.2
Event History
Jan 30, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1837?
CVE-2014-1837 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2014-1837?
To fix CVE-2014-1837, update the Komento component to version 1.7.4 or later.
3
What versions of Komento are affected by CVE-2014-1837?
CVE-2014-1837 affects Komento versions prior to 1.7.4, specifically 1.7.0, 1.7.1, and 1.7.2.
4
What type of attacks does CVE-2014-1837 allow?
CVE-2014-1837 allows remote attackers to execute arbitrary web scripts or HTML via comment injections.
5
Is there a way to mitigate CVE-2014-1837 without updating?
There are no reliable mitigations for CVE-2014-1837 other than updating to a secure version.