← Back

CVE-2014-6254

nvd nist
Published: Dec 15, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or HTML via an attribute in a (1) device name, (2) device detail, (3) report name, (4) report detail, or (5) portlet name, or (6) a string to a helper method, aka ZEN-15381 and ZEN-15410.

Affected (20)

Products: Zenoss: Zenoss Core
1 product
Zenoss Core
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Zenoss
Up to 5.0.0
Version 2.4.0
Version 2.4.5
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 3.0.0
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.1.0
Version 3.2.0
Version 3.2.1
Version 4.2.0
Version 4.2.3
Version 4.2.4
Version 4.2.5
Version 5.0.0
Version 5.0.0 beta_1
Version 5.0.0 beta_2

References (4)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.