CVE-2014-2353: Cogent DataHub XSS
Published May 30, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
12 affected components
Cogentdatahub Cogent Datahub<=7.3.4
Cogentdatahub Cogent Datahub=7.0
Cogentdatahub Cogent Datahub=7.0.2
Cogentdatahub Cogent Datahub=7.1.0
Cogentdatahub Cogent Datahub=7.1.1
Cogentdatahub Cogent Datahub=7.1.1.63
Cogentdatahub Cogent Datahub=7.1.2
Cogentdatahub Cogent Datahub=7.2.2
Cogentdatahub Cogent Datahub=7.3.0
Cogentdatahub Cogent Datahub=7.3.1
Cogentdatahub Cogent Datahub=7.3.2
Cogentdatahub Cogent Datahub=7.3.3
Remediation
Information
Cogent Real-Time Systems, Inc. has produced a new version of the
Cogent DataHub application, Version 7.3.5, that fixes three of the four
identified vulnerabilities. The updated version is available at the
following address:
http://cogentdatahub.com/Download_Software.html
Cogent
has indicated that it will not be fixing the cryptographic weaknesses
of hashed usernames and passwords because of compatibility issues with
existing systems. Cogent and the researcher agree that an effective
mitigation strategy for users is to select sufficiently strong
passwords. Cogent has indicated that password hashes can be checked for
strength using sites such as: https://crackstation.net/ .
Event History
May 30, 2014
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2353?
CVE-2014-2353 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-2353?
To remediate CVE-2014-2353, upgrade to Cogent DataHub version 7.3.5 or later.
3
What impact does CVE-2014-2353 have on my system?
CVE-2014-2353 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.
4
Which versions of Cogent DataHub are affected by CVE-2014-2353?
CVE-2014-2353 affects Cogent DataHub versions prior to 7.3.5.
5
Can CVE-2014-2353 be exploited without user interaction?
Yes, CVE-2014-2353 can potentially be exploited without user interaction through crafted URLs or phishing.