CVE-2014-5108: XSS
Published Jul 28, 2014
·Updated
Cross-site scripting (XSS) vulnerability in singlepages\downloadfile.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to index.php/downloadfile.
Affected Software
15 affected components
concrete5 concrete5=5.5.0
concrete5 concrete5=5.5.1
concrete5 concrete5=5.5.2
concrete5 concrete5=5.5.2.1
concrete5 concrete5=5.6.0
concrete5 concrete5=5.6.0.1
concrete5 concrete5=5.6.0.2
ConcreteCMS Concrete CMS=5.4.2
ConcreteCMS Concrete CMS=5.4.2.1
ConcreteCMS Concrete CMS=5.4.2.2
ConcreteCMS Concrete CMS=5.6.1
ConcreteCMS Concrete CMS=5.6.1.1
ConcreteCMS Concrete CMS=5.6.1.2
ConcreteCMS Concrete CMS=5.6.2
ConcreteCMS Concrete CMS=5.6.2.1
Event History
Jul 28, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5108?
CVE-2014-5108 is considered a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2014-5108?
To fix CVE-2014-5108, upgrade Concrete5 to version 5.6.3 or later.
3
Which versions of Concrete5 are affected by CVE-2014-5108?
CVE-2014-5108 affects Concrete5 versions 5.5.0 through 5.6.2.1.
4
What types of attacks can be executed through CVE-2014-5108?
CVE-2014-5108 allows attackers to inject arbitrary scripts or HTML into the web application via the HTTP Referer header.
5
Is user input validation affected by CVE-2014-5108?
Yes, the lack of proper input validation for the HTTP Referer header contributes to the vulnerability in CVE-2014-5108.