CVE-2014-7264
N/A
N/A
Summary
Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users Management feature in the admin component in Chyrp before 2.5.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user.email or (2) user.website field in a user registration.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000149
- http://chyrp.net/2014/11/18/chyrp-251-security-release/
- http://jvn.jp/en/jp/JVN13160869/index.html
- https://github.com/chyrp/chyrp/commit/43d1b6b266363ae7545d5d49851034eaeec7bebb
References
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000149
- http://chyrp.net/2014/11/18/chyrp-251-security-release/
- http://jvn.jp/en/jp/JVN13160869/index.html
- https://github.com/chyrp/chyrp/commit/43d1b6b266363ae7545d5d49851034eaeec7bebb
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.