vendor:
Epicor Enterprise
by:
Unknown
N/A
CVSS
N/A
Epicor Enterprise vulnerabilities
200
CWE
Product Name: Epicor Enterprise
Affected Version From: 7.4
Affected Version To: 7.4
Patch Exists: YES
Related CWE: CVE-2014-4311, CVE-2014-4312
CPE: a:epicor_software_corporation:epicor_enterprise:7.4
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=74795, https://www.infosecmatter.com/nessus-plugin-library/?id=91170, https://www.infosecmatter.com/nessus-plugin-library/?id=124970, https://www.infosecmatter.com/nessus-plugin-library/?id=91210, https://www.infosecmatter.com/nessus-plugin-library/?id=99163, https://www.infosecmatter.com/nessus-plugin-library/?id=93679, https://www.infosecmatter.com/nessus-plugin-library/?id=93148
Platforms Tested:
2014
Epicor Enterprise vulnerabilities
There are two vulnerabilities affecting Epicor Enterprise version 7.4. The first vulnerability, CVE-2014-4311, allows for password values to be accessed by observing the HTML code. The affected password values are 'Database Connection' and 'E-mail Connection'. The second vulnerability, CVE-2014-4312, allows for persistent and reflective cross-site scripting (XSS) attacks. This vulnerability allows for script injection and can result in abnormal behavior of the application.
Mitigation:
Unknown