First published: Fri Dec 19 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intrexx Portal Server | <=5.2 | |
Intrexx Portal Server | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2026 is categorized as a medium-severity cross-site scripting (XSS) vulnerability.
To remediate CVE-2014-2026, upgrade to Intrexx Professional version 5.2 Online Update 0905 or 6.0 Online Update 10 or later.
CVE-2014-2026 affects Intrexx Professional versions before 5.2 Online Update 0905 and all 6.0 versions prior to Online Update 10.
Attackers exploiting CVE-2014-2026 can inject arbitrary web scripts or HTML into the Intrexx application through the search functionality.
There are no specific workarounds for CVE-2014-2026; the recommended solution is to upgrade to the patched software version.