First published: Thu Apr 17 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall Email Security | <=7.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2879 has a high severity rating due to its potential for exploitation via cross-site scripting.
To fix CVE-2014-2879, upgrade to a version of Dell SonicWALL Email Security later than 7.4.5.
CVE-2014-2879 allows authenticated remote administrators to inject malicious scripts, which can compromise the security of the application.
CVE-2014-2879 affects users of Dell SonicWALL Email Security version 7.4.5 and earlier.
Yes, CVE-2014-2879 can be exploited remotely by authenticated users.