CVE-2014-2939: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise before 4.1.6.13 allow remote attackers to inject arbitrary web script or HTML via (1) an XHTML document, (2) a <% tag, or (3) the taskId parameter to share/page/task-edit.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2939?
CVE-2014-2939 has been classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2014-2939?
To fix CVE-2014-2939, upgrade Alfresco Enterprise to version 4.1.6.13 or later, which includes patches for the identified vulnerabilities.
What types of XSS vulnerabilities are present in CVE-2014-2939?
CVE-2014-2939 includes multiple XSS vulnerabilities through an XHTML document, a <% tag, and the taskId parameter.
Can CVE-2014-2939 be exploited remotely?
Yes, CVE-2014-2939 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
Which versions of Alfresco are affected by CVE-2014-2939?
CVE-2014-2939 affects Alfresco Enterprise versions prior to 4.1.6.13.