VDB
CVE-2014-0341
CVE-2014-0341
PUBLISHED
CVSS 3.5 LOW
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_internal/entries.tpl; (4) an event field to objects.php; or the (5) email or (6) nickname field to pages.php, related to templates_internal/users.tpl.
EPSS 0.80% · 74.4th percentile
Risk Scores
CVSS 2.0
3.5
EPSS Score
0.80%
74.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pivotx | pivotx | 2.3.3, 0, 2.1.0 |
| n/a | n/a | n/a |
Timeline
- Apr 15, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://sourceforge.net/p/pivot-weblog/code/4349/ url
- http://blog.pivotx.net/archive/2014/03/03/pivotx-239-released url
- 66800 vdb
- http://pivotx.net/page/security url
- http://sourceforge.net/p/pivot-weblog/code/4345/ url
- VU#901156 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0341 advisory
- http://sourceforge.net/p/pivot-weblog/code/4345 url
- http://sourceforge.net/p/pivot-weblog/code/4349 url