XSS Vulnerability in Xcode Server Affects Mac OS X Server by Apple
CVE-2014-4406
6.1MEDIUM
Summary
A cross-site scripting vulnerability exists in Xcode Server's CoreCollaboration component, which allows remote attackers to inject arbitrary web scripts or HTML into the application. This could lead to unauthorized access to sensitive data or execution of malicious scripts within the user's session, potentially compromising the security of the affected systems.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved