CVE-2014-4742
Published Jul 9, 2014
Last updated 10 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in system/class_link.php in the System module (module_system) in Kajona before 4.5 allows remote attackers to inject arbitrary web script or HTML via the systemid parameter in a mediaFolder action to index.php.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:kajona:kajona:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DBDF7EA-55CC-4541-9A82-FCC8C75ECB85", "versionEndIncluding": "4.4" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE6388BC-F077-4D3F-839D-33611EC25461" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "747EBA09-8276-4BFA-B832-04FD9AEE4F58" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE2C0E7E-3D1E-4206-84E2-D48ED54EDCC1" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7BF706D-9ECB-4EE1-AF96-227CBE7FB906" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2B0F01B3-E14F-4D3D-9222-20F85CCF2905" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "48EBF205-450C-412C-8285-2A74C26EE74D" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C308CB9-A481-49F3-AED2-19F01BEE4688" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCACF272-533E-4781-ACB1-0248563913ED" }, { "criteria": "cpe:2.3:a:kajona:kajona:3.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7BDD4651-6A67-4BD0-B937-C0E34C1D5014" }, { "criteria": "cpe:2.3:a:kajona:kajona:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "540FB6A6-3B7E-4181-96E7-CBFE630845B9" }, { "criteria": "cpe:2.3:a:kajona:kajona:4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1722EE1B-4A56-428A-A222-6B600D3F2ADB" }, { "criteria": "cpe:2.3:a:kajona:kajona:4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8444FA4D-2138-402F-835E-DFF562F0062C" }, { "criteria": "cpe:2.3:a:kajona:kajona:4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B4CE679-AF09-4258-88BA-8095C7DB4A87" } ], "operator": "OR" } ] } ]