CVE-2014-9905: XSS
Published Feb 17, 2017
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title of an appointment or (2) contact fields.
Affected Software
1 affected component
alinto SOGo<=2.1.1
Remediation
Patch Available
Event History
Feb 17, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-9905?
CVE-2014-9905 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-9905?
To fix CVE-2014-9905, you should update SOGo to version 2.2.0 or later.
3
What types of vulnerabilities are present in CVE-2014-9905?
CVE-2014-9905 contains multiple cross-site scripting (XSS) vulnerabilities.
4
Which software versions are affected by CVE-2014-9905?
CVE-2014-9905 affects SOGo versions prior to 2.2.0, specifically up to version 2.1.1.
5
Can CVE-2014-9905 be exploited remotely?
Yes, CVE-2014-9905 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.