CVE-2014-1648
Symantec Messaging Gateway <10.5.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.
References (4)
Scores
EPSS
0.0053
EPSS Percentile
66.8%
Details
CWE
CWE-79
Status
published
Products (7)
symantec/messaging_gateway
symantec/messaging_gateway
symantec/messaging_gateway
symantec/messaging_gateway
symantec/messaging_gateway
symantec/messaging_gateway
n/a/n/a
Published
Apr 23, 2014
Tracked Since
Feb 18, 2026