CVE-2014-3740

Spiceworks < 7.2.00190 - Authenticated Cross-Site Scripting via Ticket Summary Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3740. PoCs published by Dolev Farhi.

AI-analyzed exploit summary This exploit demonstrates multiple stored XSS vulnerabilities in SpiceWorks Ticketing system version 7.2.00174. The PoC shows how an attacker can inject malicious JavaScript into ticket titles or system settings, which executes when an admin views the tickets or settings.

Description

Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dolev Farhi · textwebappswindows
https://www.exploit-db.com/exploits/33330

This exploit demonstrates multiple stored XSS vulnerabilities in SpiceWorks Ticketing system version 7.2.00174. The PoC shows how an attacker can inject malicious JavaScript into ticket titles or system settings, which executes when an admin views the tickets or settings.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SpiceWorks Ticketing System 7.2.00174
Auth required
Prerequisites: Access to create a ticket or modify system settings · Admin user interaction to view the malicious content
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/532346/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/106916
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jun/42
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/33330
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58522

Scores

EPSS 0.0338
EPSS Percentile 87.2%

Details

CWE
CWE-79
Status published
Products (3)
spiceworks/spiceworks 7.2.00174
spiceworks/spiceworks 7.2.00189
spiceworks/spiceworks < 7.2.00190
Published Sep 11, 2014
Tracked Since Feb 18, 2026