CVE-2014-2844: XSS
Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote authenticated administrators to inject arbitrary web script or HTML via the new parameter in the SysUser module to admin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
F-Secure Messaging Secure Gatewayto a version that resolves this vulnerability.Fixed in 7.5.0Patch Patch 1862
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2844?
CVE-2014-2844 has a moderate severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-2844?
To fix CVE-2014-2844, it is recommended to apply Patch 1862 for F-Secure Messaging Secure Gateway version 7.5.0.
Who is affected by CVE-2014-2844?
CVE-2014-2844 affects remote authenticated administrators using F-Secure Messaging Secure Gateway version 7.5.0.
What type of vulnerability is CVE-2014-2844?
CVE-2014-2844 is a cross-site scripting (XSS) vulnerability that allows script injection.
What can attackers do with CVE-2014-2844?
Attackers can exploit CVE-2014-2844 to inject arbitrary web scripts or HTML into the application.