A vulnerability was found in yanheven console and classified as problematic. Affected by this issue is some unknown functionality of the file horizon/static/horizon/js/horizon.instances.js. The manipulation leads to cross site scripting. The attack may be launched remotely. The patch is identified as 32a7b713468161282f2ea01d5e2faff980d924cd. It is recommended to apply a patch to fix this issue. VDB-218354 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/yanheven/console/commit/32a7b713468161282f2ea01d5e2faff980d924cd | Patch |
https://vuldb.com/?ctiid.218354 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.218354 | Third Party Advisory |
Configurations
History
29 Feb 2024, 01:14
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
08 Dec 2023, 20:25
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-01-15 09:15
Updated : 2024-05-17 00:58
NVD link : CVE-2014-125078
Mitre link : CVE-2014-125078
CVE.ORG link : CVE-2014-125078
JSON object : View
Products Affected
horizon_project
- horizon
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')