Back to Database
Status published
Medium
CVE-2014-9677
Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the Swfile parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9677
Credits & Attribution
No credits recorded in the NVD database.
References
More from flowpaper
View All →CVE-2020-23879
pdf2json v0.71 was discovered to contain a NULL pointer dereference...
High
7.5
CVE-2020-23878
pdf2json v0.71 was discovered to contain a stack buffer overflow...
Critical
9.8
CVE-2020-19475
An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON...
Medium
5.5
CVE-2020-19474
An issue has been found in function Gfx::doShowText in PDF2JSON...
Medium
5.5
CVE-2020-19473
An issue has been found in function DCTStream::decodeImage in PDF2JSON...
Medium
5.5
Affected Vendor
flowpaper
View all reports →Affected Software
flexpaper
Vulnerable Versions:
0
Timeline
Official Publish:
October 17th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.