First published: Tue Oct 03 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module/module_frame/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EyesOfNetwork EyesOfNetwork | =5.1-0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-14985 is considered moderate due to its potential to allow XSS attacks.
To fix CVE-2017-14985, update EyesOfNetwork to the latest version or apply appropriate security patches.
Remote authenticated users of the EyesOfNetwork web interface version 5.1-0 are affected by CVE-2017-14985.
CVE-2017-14985 is a cross-site scripting (XSS) vulnerability.
CVE-2017-14985 impacts the module/module_frame/index.php component of the EyesOfNetwork web interface.