CVE-2014-1994: XSS
Published Jul 20, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
27 affected components
Cybozu Garoon=2.0.0
Cybozu Garoon=2.1.0
Cybozu Garoon=2.1.1
Cybozu Garoon=2.1.2
Cybozu Garoon=2.1.3
Cybozu Garoon=2.5.0
Cybozu Garoon=2.5.1
Cybozu Garoon=2.5.2
Cybozu Garoon=2.5.3
Cybozu Garoon=2.5.4
Cybozu Garoon=3.0.0
Cybozu Garoon=3.0.1
Cybozu Garoon=3.0.2
Cybozu Garoon=3.0.3
Cybozu Garoon=3.1.0
Cybozu Garoon=3.1.1
Cybozu Garoon=3.1.2
Cybozu Garoon=3.1.3
Cybozu Garoon=3.5.0
Cybozu Garoon=3.5.1
Cybozu Garoon=3.5.2
Cybozu Garoon=3.5.3
Cybozu Garoon=3.5.4
Cybozu Garoon=3.5.5
Cybozu Garoon=3.7-sp1
Cybozu Garoon=3.7-sp2
Cybozu Garoon=3.7-sp3
Event History
Jul 20, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What are the affected versions for CVE-2014-1994?
CVE-2014-1994 affects Cybozu Garoon versions 2.x up to 3.7 SP3.
2
What type of vulnerability is CVE-2014-1994?
CVE-2014-1994 is identified as a cross-site scripting (XSS) vulnerability.
3
Who can exploit CVE-2014-1994?
CVE-2014-1994 can be exploited by remote authenticated users.
4
How can I secure my application against CVE-2014-1994?
To mitigate CVE-2014-1994, upgrade to Cybozu Garoon version 3.7 SP4 or later.
5
What impact does CVE-2014-1994 have on my system?
CVE-2014-1994 allows attackers to inject arbitrary web scripts or HTML into the Notices portlet.