CVE Database
/

CVE-2014-4312

Back to search

CVE-2014-4312

Published: Oct 10, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote attackers to inject arbitrary web script or HTML via the (1) Notes section to Order details; (2) Description section to "Order to consume"; (3) Favorites name section to Favorites; (4) FiltKeyword parameter to Procurement/EKPHTML/search_item_bt.asp; (5) Act parameter to Procurement/EKPHTML/EnterpriseManager/Budget/ImportBudget_fr.asp; (6) hdnOpener or (7) hdnApproverFieldName parameter to Procurement/EKPHTML/EnterpriseManager/UserSearchDlg.asp; or (8) INTEGRATED parameter to Procurement/EKPHTML/EnterpriseManager/Codes.asp.

VendorProductVersions

n/a

n/a

affected
n/a

References

112470
vdb-entry
x_refsource_OSVDB
70192
vdb-entry
x_refsource_BID
112471
vdb-entry
x_refsource_OSVDB
34864
exploit
x_refsource_EXPLOIT-DB
112469
vdb-entry
x_refsource_OSVDB
112467
vdb-entry
x_refsource_OSVDB
20141001 Epicor Enterprise vulnerabilities
mailing-list
x_refsource_FULLDISC
epicor-cve20144312-xss(96793)
vdb-entry
x_refsource_XF
112464
vdb-entry
x_refsource_OSVDB
112466
vdb-entry
x_refsource_OSVDB
112465
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now