VYPR
Unrated severityNVD Advisory· Published Feb 23, 2019· Updated Aug 6, 2024

CVE-2014-10078

CVE-2014-10078

Description

Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

Root cause

"Missing output sanitization of the `cn` and `result` query parameters allows arbitrary HTML/JavaScript injection."

Attack vector

An unauthenticated attacker crafts a URL containing a malicious JavaScript payload in the `cn` or `result` parameter and tricks a victim into clicking it [ref_id=1]. The payload is injected by closing an existing `<font>` tag and inserting a `<script>` block, e.g., `?cn=</font><script>alert(1);</script><font>` [ref_id=1]. The attack requires no authentication and is delivered over the StoreGrid web interface on port 6061 [ref_id=1].

Affected code

The vulnerable files are `interface/registercustomer/onlineregsuccess.php`, `interface/registerreseller/onlineregfailure.php`, `interface/registerclient/onlineregfailure.php`, and `interface/registercustomer/onlineregfailure.php` [ref_id=1]. These PHP scripts reflect user-supplied `cn` and `result` query parameters without sanitization.

What the fix does

No patch is included in the bundle. The advisory does not specify a fix version or remediation steps [ref_id=1][ref_id=2]. To close the vulnerability, the application must properly encode or sanitize the `cn` and `result` parameters before reflecting them in the HTML output, preventing script injection.

Preconditions

  • inputThe attacker must trick a victim into visiting a crafted URL on the StoreGrid web interface (port 6061).
  • authNo authentication is required to trigger the XSS.

Reproduction

1. Access the StoreGrid web interface on port 6061. 2. Visit a URL such as `https://target:6061/interface/registercustomer/onlineregsuccess.php?cn=</font><script>alert(1);</script><font>&result=` [ref_id=1]. 3. Observe that the JavaScript `alert(1)` executes in the browser, confirming reflected XSS.

Generated on May 26, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

3

News mentions

0

No linked articles in our index yet.