CVE-2014-9469: XSS
Published Aug 28, 2017
·Updated
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
Affected Software
7 affected components
vBulletin vBulletin=3.5.4
vBulletin vBulletin=3.6
vBulletin vBulletin=3.6.7
vBulletin vBulletin=3.8.7
vBulletin vBulletin=4.2.2
vBulletin vBulletin=5.0.5
vBulletin vBulletin=5.1.3
Event History
Aug 28, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9469?
CVE-2014-9469 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-9469?
To fix CVE-2014-9469, upgrade your vBulletin installation to a version that is not affected by this vulnerability.
3
Which versions of vBulletin are affected by CVE-2014-9469?
CVE-2014-9469 affects vBulletin versions 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
4
What types of attacks can CVE-2014-9469 enable?
CVE-2014-9469 can enable attackers to perform cross-site scripting (XSS) attacks, potentially allowing them to execute arbitrary scripts in the context of the user's browser.
5
Is there a patch available for CVE-2014-9469?
Yes, a patch is included in the updated versions of vBulletin that have addressed CVE-2014-9469.