Skip to content

CVE-2014-3740

Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0228 (2.3%)
Percentile: 84.8%
EPSS: 2026-05-06

Affects

spiceworks:spiceworks

Technical description

Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.

Published: 9/11/2014, 6:55:05 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam