← Back

CVE-2014-8772

nvd nist
Published: Dec 3, 2014Modified: May 6, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticated users to inject arbitrary web script or HTML via the search parameter.

Affected (2)

Products: X3cms: X3 Cms
1 product
X3 Cms
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
X3cms
Version 0.5.1.1
Version 0.5.1

References (4)

Timeline

No history available yet.