First published: Fri Apr 04 2014(Updated: )
Cross-site scripting (XSS) vulnerability in UserServlet in Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun24384.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | <=8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2114 has a medium severity rating due to its potential for remote exploitation.
To fix CVE-2014-2114, upgrade Cisco Emergency Responder to version 8.6 or later, which addresses the vulnerability.
CVE-2014-2114 affects Cisco Emergency Responder versions up to and including 8.6.
CVE-2014-2114 is classified as a cross-site scripting (XSS) vulnerability.
Attackers can exploit CVE-2014-2114 to inject arbitrary web scripts or HTML into the application.