CVE-2014-2114: XSS
Published Apr 4, 2014
·Updated
Cross-site scripting (XSS) vulnerability in UserServlet in Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun24384.
Affected Software
1 affected component
Cisco Emergency Responder<=8.6
Event History
Apr 4, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:10 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2114?
CVE-2014-2114 has a medium severity rating due to its potential for remote exploitation.
2
How do I fix CVE-2014-2114?
To fix CVE-2014-2114, upgrade Cisco Emergency Responder to version 8.6 or later, which addresses the vulnerability.
3
What systems are affected by CVE-2014-2114?
CVE-2014-2114 affects Cisco Emergency Responder versions up to and including 8.6.
4
What type of vulnerability is CVE-2014-2114?
CVE-2014-2114 is classified as a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2014-2114?
Attackers can exploit CVE-2014-2114 to inject arbitrary web scripts or HTML into the application.