Skip to content

Ajenti Cross-site scripting (XSS) vulnerability

Low severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated May 1, 2024

Package

pip ajenti (pip)

Affected versions

< 1.2.15

Patched versions

1.2.15

Description

Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Ajenti before 1.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.

References

Published by the National Vulnerability Database Apr 30, 2014
Published to the GitHub Advisory Database May 17, 2022
Reviewed May 1, 2024
Last updated May 1, 2024

Severity

Low

Weaknesses

CVE ID

CVE-2014-2260

GHSA ID

GHSA-9crx-p357-5vw8

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.