Vulnerability Details CVE-2014-0341
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_internal/entries.tpl; (4) an event field to objects.php; or the (5) email or (6) nickname field to pages.php, related to templates_internal/users.tpl.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.3%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2014-0341
-
cpe:2.3:a:pivotx:pivotx:2.1.0
-
cpe:2.3:a:pivotx:pivotx:2.1.1
-
cpe:2.3:a:pivotx:pivotx:2.1.2
-
cpe:2.3:a:pivotx:pivotx:2.2.0
-
cpe:2.3:a:pivotx:pivotx:2.2.1
-
cpe:2.3:a:pivotx:pivotx:2.2.2
-
cpe:2.3:a:pivotx:pivotx:2.2.3
-
cpe:2.3:a:pivotx:pivotx:2.2.5
-
cpe:2.3:a:pivotx:pivotx:2.3.0
-
cpe:2.3:a:pivotx:pivotx:2.3.2
-
cpe:2.3:a:pivotx:pivotx:2.3.3
-
cpe:2.3:a:pivotx:pivotx:2.3.5
-
cpe:2.3:a:pivotx:pivotx:2.3.6
-
cpe:2.3:a:pivotx:pivotx:2.3.7
-
cpe:2.3:a:pivotx:pivotx:2.3.8