Unrated severityNVD Advisory· Published Feb 11, 2014· Updated Apr 29, 2026
CVE-2014-1237
CVE-2014-1237
Description
Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the call parameter.
Affected products
5cpe:2.3:a:i-doit:i-doit:1.1.1:*:*:*:pro:*:*:*+ 4 more
- cpe:2.3:a:i-doit:i-doit:1.1.1:*:*:*:pro:*:*:*
- cpe:2.3:a:i-doit:i-doit:1.1.2:*:*:*:pro:*:*:*
- cpe:2.3:a:i-doit:i-doit:1.2.1:*:*:*:pro:*:*:*
- cpe:2.3:a:i-doit:i-doit:1.2.2:*:*:*:pro:*:*:*
- cpe:2.3:a:i-doit:i-doit:*:*:*:*:pro:*:*:*range: <=1.2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/56834nvdVendor Advisory
- www.i-doit.com/en/company/news/single-news/nvdVendor Advisory
- osvdb.org/102910nvd
- packetstormsecurity.com/files/125062nvd
- seclists.org/fulldisclosure/2014/Feb/26nvd
- secunia.com/advisories/56802nvd
- www.csnc.ch/misc/files/advisories/CVE-2014-1237_i-doit_Cross-site_Scripting_-_XSS.txtnvd
- www.securityfocus.com/bid/65353nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/90969nvd
News mentions
0No linked articles in our index yet.