CVE-2014-3247 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.7% (pctl 77)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.74% — more likely to be exploited than 77% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-05-15 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| o-dyn | collabtive |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Collabtive 1.2 - Persistent Cross-Site Scripting | 2014-05-08 |
References
→ the Explorer · watch your stack · NVD