First published: Fri Sep 26 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Telerik UI for ASP.NET AJAX RadEditor control 2014.1.403.35, 2009.3.1208.20, and other versions allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik UI for ASP.NET AJAX | <=2014.1.403.35 | |
Telerik UI for ASP.NET AJAX | =2009.3.1208.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4958 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-4958, update to a version of Telerik UI for ASP.NET AJAX RadEditor that is later than 2014.1.403.35.
CVE-2014-4958 affects Telerik UI for ASP.NET AJAX RadEditor versions up to 2014.1.403.35 and specifically version 2009.3.1208.20.
CVE-2014-4958 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts through style attributes.
CVE-2014-4958 can be exploited by remote attackers who are able to inject malicious scripts into web applications using vulnerable versions of Telerik RadEditor.