CVE-2014-4661

HP Records Manager <7.3.5, <8.1-8.1 Patch 3 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in HP Records Manager before 7.3.5 and 8.x before 8.1 Patch 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

References (3)

Core 3
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/683972
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70286

Scores

EPSS 0.0138
EPSS Percentile 80.6%

Details

CWE
CWE-79
Status published
Products (2)
hp/records_manager 8.1 (3 CPE variants)
hp/records_manager < 7.3.4
Published Oct 10, 2014
Tracked Since Feb 18, 2026