CVE-2014-8069: XSS
Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to index.php/user or (2) PATHINFO to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8069?
CVE-2014-8069 is classified as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary scripts.
How do I fix CVE-2014-8069?
To fix CVE-2014-8069, it is recommended to upgrade to the latest version of YOOtheme Pagekit that addresses these vulnerabilities.
What are the risks associated with CVE-2014-8069?
The risks of CVE-2014-8069 include unauthorized data access, session hijacking, and website defacement due to XSS exploitation.
Who is affected by CVE-2014-8069?
CVE-2014-8069 affects users of YOOtheme Pagekit CMS version 0.8.7 and potentially any applications that utilize this version.
What types of attacks can CVE-2014-8069 facilitate?
CVE-2014-8069 can facilitate various types of attacks including cross-site scripting (XSS), which may lead to data theft and user impersonation.