CVE-2014-5326

Description

Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.217

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-5326,CVE-2014-5325 are fixed in Direct-Web-Remoting-dwr 3.0Windows
Vulnerabilities CVE-2014-5326,CVE-2014-5325 are fixed in Direct-Web-Remoting-dwr 2.0.11Windows
Vulnerabilities CVE-2014-5326,CVE-2014-5325 are fixed in Direct-Web-Remoting-dwr for Linux 3.0Linux
Vulnerabilities CVE-2014-5326,CVE-2014-5325 are fixed in Direct-Web-Remoting-dwr for Linux 2.0.11Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234