CVE-2014-125070
yanheven console tables.py AvailabilityZonesTable cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been found in yanheven console and classified as problematic. Affected by this vulnerability is the function get_zone_hosts/AvailabilityZonesTable of the file openstack_dashboard/dashboards/admin/aggregates/tables.py. The manipulation leads to cross site scripting. The attack can be launched remotely. The patch is named ba908ae88d5925f4f6783eb234cc4ea95017472b. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217651.
Se ha encontrado una vulnerabilidad en yanheven console y ha sido clasificada como problemática. La función get_zone_hosts/AvailabilityZonesTable del archivo openstack_dashboard/dashboards/admin/aggregates/tables.py es afectada por esta vulnerabilidad. La manipulación conduce a cross-site scripting. El ataque se puede lanzar de forma remota. El parche se llama ba908ae88d5925f4f6783eb234cc4ea95017472b. Se recomienda aplicar un parche para solucionar este problema. El identificador asociado de esta vulnerabilidad es VDB-217651.
In yanheven console wurde eine Schwachstelle gefunden. Sie wurde als problematisch eingestuft. Das betrifft die Funktion get_zone_hosts/AvailabilityZonesTable der Datei openstack_dashboard/dashboards/admin/aggregates/tables.py. Mittels dem Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Patch wird als ba908ae88d5925f4f6783eb234cc4ea95017472b bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-08 CVE Reserved
- 2023-01-08 CVE Published
- 2024-07-31 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.217651 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/yanheven/console/commit/ba908ae88d5925f4f6783eb234cc4ea95017472b | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Console Project Search vendor "Console Project" | Console Search vendor "Console Project" for product "Console" | < 2014-08-19 Search vendor "Console Project" for product "Console" and version " < 2014-08-19" | - |
Affected
|