CVE-2014-4036: XSS
A cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a listimg action.
Other sources
Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a listimg action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4036?
CVE-2014-4036 is classified as a moderate severity vulnerability due to its potential impact on user security through cross-site scripting.
How do I fix CVE-2014-4036?
To fix CVE-2014-4036, you should upgrade ImpressCMS to a version later than 1.3.6.1 where the vulnerability is patched.
What systems are affected by CVE-2014-4036?
CVE-2014-4036 specifically affects ImpressCMS version 1.3.6.1.
What type of vulnerability is CVE-2014-4036?
CVE-2014-4036 is a cross-site scripting (XSS) vulnerability.
Can CVE-2014-4036 be exploited remotely?
Yes, CVE-2014-4036 can be exploited remotely by attackers through malicious input.