CVE-2014-2260: XSS
Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Ajenti before 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
Other sources
Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/ajentito a version that resolves this vulnerability.Fixed in 1.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2260?
CVE-2014-2260 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-2260?
To fix CVE-2014-2260, upgrade Ajenti to version 1.2.15 or later.
What impact does CVE-2014-2260 have on systems?
CVE-2014-2260 allows remote authenticated users to inject arbitrary web scripts or HTML, potentially compromising the integrity of affected systems.
Which versions of Ajenti are affected by CVE-2014-2260?
Ajenti versions prior to 1.2.15, including 1.2.13, are affected by CVE-2014-2260.
Who can exploit CVE-2014-2260?
CVE-2014-2260 can be exploited by remote authenticated users of Ajenti.