CVE-2014-4037: XSS
Published Jun 11, 2014
·Updated
Cross-site scripting (XSS) vulnerability in editor/dialog/fckspellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an array key in the textinputs[] parameter, a different issue than CVE-2012-4000.
Affected Software
1 affected component
CKEditor FCKeditor<=2.6.10
Remediation
Patch Available
Event History
Jun 11, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-4037?
CVE-2014-4037 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2014-4037?
To fix CVE-2014-4037, update FCKeditor to version 2.6.11 or later.
3
What software is affected by CVE-2014-4037?
CVE-2014-4037 affects FCKeditor versions prior to 2.6.11.
4
What types of attacks can CVE-2014-4037 enable?
CVE-2014-4037 can allow an attacker to inject arbitrary web scripts or HTML into web pages.
5
Where can I find more information about CVE-2014-4037?
More detailed information about CVE-2014-4037 can typically be found in security advisories and technical reports.