CVE-2017-14922
Summary
| CVE | CVE-2017-14922 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-30 01:29:00 UTC |
| Updated | 2017-10-05 18:43:00 UTC |
| Description | Stored XSS vulnerability via IMG element at "History" of Profile, Calendar, Tasks, and CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Releases · tine20/Tine-2.0-Open-Source-Groupware-and-CRM · GitHub | MISC | github.com | Issue Tracking, Patch, Release Notes, Third Party Advisory |
| node exists exception broken · tine20/tine20@24e39e1 · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| node delte might fail · tine20/tine20@146c5aa · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| name might not be displayed correctly · tine20/tine20@bc8a6fb · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| oss-security - Stored XSS vulnerability in Tine 2.0 Community Edition <= 2017.08.3 | MISC | openwall.com | Mailing List, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.