{"api_version":"1","generated_at":"2026-07-23T04:34:56+00:00","cve":"CVE-2014-5322","urls":{"html":"https://cve.report/CVE-2014-5322","api":"https://cve.report/api/cve/CVE-2014-5322.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-5322","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-5322"},"summary":{"title":"CVE-2014-5322","description":"Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-3640.","state":"PUBLISHED","assigner":"jpcert","published_at":"2014-09-22 01:55:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/69987","name":"http://www.securityfocus.com/bid/69987","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FileMaker Pro and FileMaker Pro Advanced Incomplete Fix Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1030880","name":"http://www.securitytracker.com/id/1030880","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FileMaker Pro Input Validation Flaw in 'Instant Web Publish' Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN53579095/index.html","name":"http://jvn.jp/en/jp/JVN53579095/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"JVN#53579095: FileMaker Pro vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000113","name":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000113","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-5322","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5322","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"5322","vulnerable":"1","versionEndIncluding":"12.0.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"filemaker","cpe5":"filemaker_pro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5322","vulnerable":"1","versionEndIncluding":"12.0.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"filemaker","cpe5":"filemaker_pro_advanced","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:41:48.621Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1030880","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030880"},{"name":"JVN#53579095","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN53579095/index.html"},{"name":"69987","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/69987"},{"name":"JVNDB-2014-000113","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000113"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-09-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-3640."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-04-29T18:57:00.000Z","orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert"},"references":[{"name":"1030880","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030880"},{"name":"JVN#53579095","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN53579095/index.html"},{"name":"69987","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/69987"},{"name":"JVNDB-2014-000113","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000113"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2014-5322","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-3640."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1030880","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030880"},{"name":"JVN#53579095","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN53579095/index.html"},{"name":"69987","refsource":"BID","url":"http://www.securityfocus.com/bid/69987"},{"name":"JVNDB-2014-000113","refsource":"JVNDB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000113"}]}}}},"cveMetadata":{"assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","cveId":"CVE-2014-5322","datePublished":"2014-09-22T01:00:00.000Z","dateReserved":"2014-08-18T00:00:00.000Z","dateUpdated":"2024-08-06T11:41:48.621Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-09-22 01:55:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:filemaker:filemaker_pro:*:*:*:*:*:*:*:*","versionEndIncluding":"12.0.0.0","matchCriteriaId":"9FCE7435-075A-431D-9ADB-7D34AF5CD7D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:filemaker:filemaker_pro_advanced:*:*:*:*:*:*:*:*","versionEndIncluding":"12.0.0.0","matchCriteriaId":"220982EA-BFEF-4D14-8B4F-E0B36822B2F2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"5322","Ordinal":"1","Title":"CVE-2014-5322","CVE":"CVE-2014-5322","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"5322","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-3640.","Type":"Description","Title":"CVE-2014-5322"},{"CveYear":"2014","CveId":"5322","Ordinal":"2","NoteData":"2014-09-21","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"5322","Ordinal":"3","NoteData":"2015-04-29","Type":"Other","Title":"Modified"}]}}}