CVE-2014-2021: XSS
Published Oct 25, 2014
·Updated
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.
Affected Software
7 affected components
vBulletin vBulletin<=4.2.2
vBulletin vBulletin=5.0.0
vBulletin vBulletin=5.0.1
vBulletin vBulletin=5.0.2
vBulletin vBulletin=5.0.3
vBulletin vBulletin=5.0.4
vBulletin vBulletin=5.0.5
Event History
Oct 25, 2014
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2021?
CVE-2014-2021 is classified as a high-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-2021?
To fix CVE-2014-2021, upgrade to vBulletin version 5.0.6 or later.
3
Which versions of vBulletin are affected by CVE-2014-2021?
CVE-2014-2021 affects vBulletin versions 4.2.2 and earlier and 5.0.x up to 5.0.5.
4
Can CVE-2014-2021 be exploited by unauthenticated users?
No, CVE-2014-2021 can only be exploited by remote authenticated users.
5
What impact does CVE-2014-2021 have on web applications?
CVE-2014-2021 allows for remote authenticated users to inject arbitrary web scripts or HTML, potentially compromising the security of the application.