CVE-2014-6254: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or HTML via an attribute in a (1) device name, (2) device detail, (3) report name, (4) report detail, or (5) portlet name, or (6) a string to a helper method, aka ZEN-15381 and ZEN-15410.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6254?
CVE-2014-6254 is ultimately rated as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2014-6254?
To fix CVE-2014-6254, it is recommended to upgrade to Zenoss Core versions that are higher than 5.0.0 Beta 3 and to sanitize user input.
Which versions of Zenoss Core are affected by CVE-2014-6254?
CVE-2014-6254 affects multiple versions of Zenoss Core including all versions from 2.4.0 to 5.0.0 Beta 3.
What types of user input can be exploited in CVE-2014-6254?
CVE-2014-6254 can be exploited through attributes in device names, device details, report names, report details, portlet names, and strings to helper methods.
Can CVE-2014-6254 lead to data theft?
Yes, CVE-2014-6254 can potentially lead to data theft by injecting malicious scripts that capture sensitive user information.