First published: Wed Apr 30 2014(Updated: )
Cross-site scripting (XSS) vulnerability in `plugins/main/content/js/ajenti.coffee` in Ajenti before 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/ajenti | <1.2.15 | 1.2.15 |
Mentiss Acgv Acgvannu | =1.2.13 | |
=1.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2260 is classified as a high severity cross-site scripting (XSS) vulnerability.
To fix CVE-2014-2260, upgrade Ajenti to version 1.2.15 or later.
CVE-2014-2260 allows remote authenticated users to inject arbitrary web scripts or HTML, potentially compromising the integrity of affected systems.
Ajenti versions prior to 1.2.15, including 1.2.13, are affected by CVE-2014-2260.
CVE-2014-2260 can be exploited by remote authenticated users of Ajenti.