CVE-2014-5024: XSS
Published Jul 24, 2014
·Updated
Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the nodeid parameter.
Affected Software
3 affected components
SonicWall Analyzer<=7.2
SonicWall Global Management System<=7.2
SonicWall UMA EM5000
Event History
Jul 24, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5024?
CVE-2014-5024 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-5024?
To fix CVE-2014-5024, upgrade to SonicWALL GMS, Analyzer, or UMA version 7.2 SP1 or later.
3
What types of software are affected by CVE-2014-5024?
CVE-2014-5024 affects SonicWALL GMS, Analyzer, and UMA versions up to 7.2.
4
Can attackers exploit CVE-2014-5024 remotely?
Yes, attackers can exploit CVE-2014-5024 remotely through crafted requests to the affected web interface.
5
What can attackers do by exploiting CVE-2014-5024?
By exploiting CVE-2014-5024, attackers can inject arbitrary web scripts or HTML into the application's interface.