CVE-2014-3111: XSS
Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Printer Model field to the Printer Management page, (2) Image Name field to the Image Management page, (3) Storage Group Name field to the Storage Management page, (4) Username field to the User Cleanup FOG Configuration page, or (5) Directory Path field to the Directory Cleaner FOG Configuration page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3111?
CVE-2014-3111 is classified as a medium severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2014-3111?
To mitigate CVE-2014-3111, upgrade to a version of FOG beyond 0.32 which addresses these XSS vulnerabilities.
What types of XSS vulnerabilities are present in CVE-2014-3111?
CVE-2014-3111 contains multiple stored cross-site scripting vulnerabilities that allow attackers to inject arbitrary web scripts.
Which versions of FOG are affected by CVE-2014-3111?
CVE-2014-3111 affects FOG versions 0.27 through 0.32.
Who can exploit CVE-2014-3111?
CVE-2014-3111 can be exploited by remote authenticated users within the FOG application.