CVE-2014-2260

low
Published 2014-04-30 · Modified 2024-05-01
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2
3.5
VIR risk
3.5

Description

Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/Eugeny/ajenti/commit/3270fd1d78391bb847b4c9ce37cf921f485b1310

Package impact

EcosystemPackageVulnerableFixed
python PyPIajenti<1.2.151.2.15
python PyPIajenti<3270fd1d78391bb847b4c9ce37cf921f485b1310||<1.2.143270fd1d78391bb847b4c9ce37cf921f485b1310

Application impact

VendorProductVersionsFixed
ajentiajenti1.2.13

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.