VDB

GCVE-110-CERTCC-2014-901156

GCVE-110-CERTCC-2014-901156
Advisory PublishedCVSS 6.5/10
Vulnetix · Advisory published March 5, 2014
PivotX 2.3.8, and possibly earlier versions, contains cross-site scripting (CWE-79) and unsafe file upload (CWE-434) vulnerabilities.

Risk Scores

CVSS 2.0
6.5/10
Medium · AV:N/AC:L/Au:S/C:P/I:P/A:P
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_impact3d1_population3d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score5.1remediation_levelOFreport_confidenceCenvironmental_score1.27683519756581target_distributionLenvironmental_vectorCDP:ND/TD:L/CR:ND/IR:ND/AR:ND

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›