3.5
CVSSv2

CVE-2014-3740

Published: 11/09/2014 Updated: 10/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in SpiceWorks prior to 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spiceworks spiceworks

spiceworks spiceworks 7.2.00189

spiceworks spiceworks 7.2.00174

Exploits

# Exploit Title: Multiple Stored XSS vulnerabilities in SpiceWorks Ticketing system # Date: 12/05/2014 # Exploit author: Dolev Farhi @f1nhack # Vendor homepage: spiceworkscom # Software Link: downloadspiceworkscom/Spiceworksexe # Version: 7200174 (Latest) # Tested on: Kali Linux # Vendor alerted: 12/05/2014 1 About the applica ...
SpiceWorks IT Ticketing System versions prior to 7200195 suffer from multiple persistent cross site scripting vulnerabilities ...