CVE-2014-2670: XSS
Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter, a different vulnerability than CVE-2014-0344.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2670?
CVE-2014-2670 has a medium CVSS score indicating its potential to cause moderate impact if exploited.
How do I fix CVE-2014-2670?
To mitigate CVE-2014-2670, upgrade ZOHO ManageEngine OpStor to the latest patched version beyond build 8500.
Who is affected by CVE-2014-2670?
Only remote authenticated users of ZOHO ManageEngine OpStor versions up to 8.3 are impacted by CVE-2014-2670.
What type of vulnerability is CVE-2014-2670?
CVE-2014-2670 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.
Can CVE-2014-2670 allow data theft?
Yes, if exploited, CVE-2014-2670 can lead to unauthorized data access by injecting malicious scripts.