CVE-2014-1223

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
27/02/2014
Last modified:
12/04/2025

Description

Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162, 7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:telligent:evolution:*:*:*:*:*:*:*:* 6.1 (including) 6.1.19.36103 (excluding)
cpe:2.3:a:telligent:evolution:*:*:*:*:*:*:*:* 7.1 (including) 7.1.12.36162 (excluding)
cpe:2.3:a:telligent:evolution:*:*:*:*:*:*:*:* 7.5 (including) 7.5.0.32466 (including)
cpe:2.3:a:telligent:evolution:*:*:*:*:*:*:*:* 7.6 (including) 7.6.7.36651 (excluding)