4.3
CVSSv2

CVE-2014-3247

Published: 15/05/2014 Updated: 01/08/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

o-dyn collabtive 1.2

Vendor Advisories

Debian Bug report logs - #748828 collabtive: CVE-2014-3246 CVE-2014-3247 Package: src:collabtive; Maintainer for src:collabtive is Gunnar Wolf <gwolf@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 21 May 2014 05:21:02 UTC Severity: grave Tags: security, upstream Fixed in version collab ...

Exploits

Vulnerability title: Stored XSS vulnerability in Collabtive application (CVE-2014-3247) CVE: CVE-2014-3247(coordinated with cve assigning team and vendor) Vendor: Collabtive Product: Collabtive (Open Source Project Management Software) Affected version: 112 Fixed version: 20 Reported by: Deepak Rathore Severity: Critical URL: [domain]/coll ...