{"api_version":"1","generated_at":"2026-05-12T03:51:50+00:00","cve":"CVE-2014-2879","urls":{"html":"https://cve.report/CVE-2014-2879","api":"https://cve.report/api/cve/CVE-2014-2879.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2879","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2879"},"summary":{"title":"CVE-2014-2879","description":"Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-04-17 14:55:12","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/531642/100/0/threaded","name":"http://www.securityfocus.com/archive/1/531642/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1029965","name":"http://www.securitytracker.com/id/1029965","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SonicWALL Email Security Input Validation Flaw in 'License Management' and 'Advanced' Pages Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/66501","name":"http://www.securityfocus.com/bid/66501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Dell SonicWall EMail Security Appliance Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://seclists.org/fulldisclosure/2014/Mar/409","name":"http://seclists.org/fulldisclosure/2014/Mar/409","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: Dell SonicWall EMail Security 7.4.5 - Multiple Vulnerabilities\t(Bulletin)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.sonicwall.com/us/shared/download/Support-Bulletin_Email-Security_Scripting_Vulnerability__Resolved_in__ES746.pdf","name":"http://www.sonicwall.com/us/shared/download/Support-Bulletin_Email-Security_Scripting_Vulnerability__Resolved_in__ES746.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Page Not Found","mime":"application/pdf","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vulnerability-lab.com/get_content.php?id=1191","name":"http://www.vulnerability-lab.com/get_content.php?id=1191","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"403 Forbidden","mime":"text/plain","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2879","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2879","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"2879","vulnerable":"1","versionEndIncluding":"7.4.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sonicwall","cpe5":"email_security_appliance","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:28:46.334Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1029965","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1029965"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.vulnerability-lab.com/get_content.php?id=1191"},{"name":"20140327 Dell SonicWall EMail Security Appliance Application v7.4.5 - Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/531642/100/0/threaded"},{"name":"66501","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/66501"},{"name":"20140328 Dell SonicWall EMail Security 7.4.5 - Multiple Vulnerabilities (Bulletin)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Mar/409"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.sonicwall.com/us/shared/download/Support-Bulletin_Email-Security_Scripting_Vulnerability__Resolved_in__ES746.pdf"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-03-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1029965","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1029965"},{"tags":["x_refsource_MISC"],"url":"http://www.vulnerability-lab.com/get_content.php?id=1191"},{"name":"20140327 Dell SonicWall EMail Security Appliance Application v7.4.5 - Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/531642/100/0/threaded"},{"name":"66501","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/66501"},{"name":"20140328 Dell SonicWall EMail Security 7.4.5 - Multiple Vulnerabilities (Bulletin)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2014/Mar/409"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.sonicwall.com/us/shared/download/Support-Bulletin_Email-Security_Scripting_Vulnerability__Resolved_in__ES746.pdf"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-2879","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1029965","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1029965"},{"name":"http://www.vulnerability-lab.com/get_content.php?id=1191","refsource":"MISC","url":"http://www.vulnerability-lab.com/get_content.php?id=1191"},{"name":"20140327 Dell SonicWall EMail Security Appliance Application v7.4.5 - Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/531642/100/0/threaded"},{"name":"66501","refsource":"BID","url":"http://www.securityfocus.com/bid/66501"},{"name":"20140328 Dell SonicWall EMail Security 7.4.5 - Multiple Vulnerabilities (Bulletin)","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2014/Mar/409"},{"name":"http://www.sonicwall.com/us/shared/download/Support-Bulletin_Email-Security_Scripting_Vulnerability__Resolved_in__ES746.pdf","refsource":"CONFIRM","url":"http://www.sonicwall.com/us/shared/download/Support-Bulletin_Email-Security_Scripting_Vulnerability__Resolved_in__ES746.pdf"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-2879","datePublished":"2014-04-17T14:00:00.000Z","dateReserved":"2014-04-17T00:00:00.000Z","dateUpdated":"2024-08-06T10:28:46.334Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-04-17 14:55:12","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:email_security_appliance:*:*:*:*:*:*:*:*","versionEndIncluding":"7.4.5","matchCriteriaId":"62886FC0-9692-42B9-9CB8-D182C20BC2A6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2879","Ordinal":"1","Title":"CVE-2014-2879","CVE":"CVE-2014-2879","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2879","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.","Type":"Description","Title":"CVE-2014-2879"},{"CveYear":"2014","CveId":"2879","Ordinal":"2","NoteData":"2014-04-17","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2879","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}