CVE-2014-100013
clientresponse 4.1 - Cross-Site Scripting via Subject or Message Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-100013. PoCs published by Halil Dalabasmaz.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in clientResponse Client Management v4.1. The vulnerability allows attackers to inject malicious scripts via the 'Subject' and 'Message' inputs, which execute when viewed by an admin.
Description
Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject or (2) Message field.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in clientResponse Client Management v4.1. The vulnerability allows attackers to inject malicious scripts via the 'Subject' and 'Message' inputs, which execute when viewed by an admin.