peter bassill · operator
$ cve CVE-2014-9522 JSON

CVE-2014-9522 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject arbitrary web script or HTML via the (1) author field to guestbook.php or (2) username field to account.php.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.5% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2015-01-05
Last modified2026-06-17

Affected (1)

VendorProduct
papoocms papoo light

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD