CVE-2014-9243: XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERYSTRING to wb/admin/admintools/tool.php or (2) sectionid parameter to editmodulefiles.php, (3) news/addpost.php, (4) news/modifygroup.php, (5) news/modifypost.php, or (6) news/modifysettings.php in wb/modules/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9243?
CVE-2014-9243 has been classified as a high severity vulnerability due to its potential for remote exploitation through cross-site scripting (XSS).
How do I fix CVE-2014-9243?
To fix CVE-2014-9243, upgrade to a version of WebsiteBaker that is not vulnerable, as version 2.8.3 is affected by multiple XSS vulnerabilities.
What are the attack vectors for CVE-2014-9243?
The attack vectors for CVE-2014-9243 include the QUERY_STRING parameter in wb/admin/admintools/tool.php and the section_id parameter in several other PHP scripts.
Who is affected by CVE-2014-9243?
CVE-2014-9243 affects users of WebsiteBaker version 2.8.3, allowing attackers to exploit the vulnerabilities to inject malicious scripts.
What kind of attacks can CVE-2014-9243 facilitate?
CVE-2014-9243 can facilitate cross-site scripting (XSS) attacks, potentially allowing attackers to execute arbitrary scripts in the context of users visiting the vulnerable site.