CVE-2014-100013

clientresponse 4.1 - Cross-Site Scripting via Subject or Message Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-100013. PoCs published by Halil Dalabasmaz.

AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in clientResponse Client Management v4.1. The vulnerability allows attackers to inject malicious scripts via the 'Subject' and 'Message' inputs, which execute when viewed by an admin.

Description

Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject or (2) Message field.

Exploits (1)

exploitdb WRITEUP
by Halil Dalabasmaz · textwebappsmultiple
https://www.exploit-db.com/exploits/35248

This is a writeup describing a stored XSS vulnerability in clientResponse Client Management v4.1. The vulnerability allows attackers to inject malicious scripts via the 'Subject' and 'Message' inputs, which execute when viewed by an admin.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: clientResponse Client Management v4.1
Auth required
Prerequisites: Access to the message system · Admin interaction required for payload execution
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35248
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/98734

Scores

EPSS 0.0146
EPSS Percentile 70.3%

Details

CWE
CWE-79
Status published
Products (1)
clientresponse_project/clientresponse 4.1
Published Jan 13, 2015
Tracked Since Feb 18, 2026