CVE-2014-5391: XSS
Published Sep 11, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash).
Affected Software
5 affected components
SOS JobScheduler<=1.6.4131
SOS JobScheduler=1.6.4014
SOS JobScheduler=1.6.4043
SOS JobScheduler=1.7.4177
SOS JobScheduler=1.7.4189
Remediation
Event History
Sep 11, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5391?
CVE-2014-5391 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2014-5391?
To resolve CVE-2014-5391, upgrade your SOS JobScheduler to version 1.6.4246 or higher, or 1.7.4241 or higher.
3
What versions of SOS JobScheduler are affected by CVE-2014-5391?
CVE-2014-5391 affects SOS JobScheduler versions prior to 1.6.4246 and 1.7.x before 1.7.4241.
4
Can CVE-2014-5391 allow remote attacks?
Yes, CVE-2014-5391 allows remote attackers to inject arbitrary web scripts or HTML into the application.
5
What property does CVE-2014-5391 exploit for XSS?
CVE-2014-5391 exploits the hash property (location.hash) to perform cross-site scripting attacks.