Vulnerability Details CVE-2014-1223
Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162, 7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.6%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-1223
-
cpe:2.3:a:telligent:evolution:6.1.19
-
cpe:2.3:a:telligent:evolution:7.1
-
cpe:2.3:a:telligent:evolution:7.1.12
-
cpe:2.3:a:telligent:evolution:7.5
-
cpe:2.3:a:telligent:evolution:7.5.0
-
cpe:2.3:a:telligent:evolution:7.5.0.32466
-
cpe:2.3:a:telligent:evolution:7.6
-
cpe:2.3:a:telligent:evolution:7.6.7