VYPR
Unrated severityNVD Advisory· Published Apr 25, 2014· Updated Jun 17, 2026

CVE-2014-2729

CVE-2014-2729

Description

Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects tab in the View Properties menu option.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.