CVE-2014-2670 is a Cross-Site Scripting (XSS) vulnerability affecting ZOHO ManageEngine OpStor before build 8500, specifically within the Properties.do component. This vulnerability allows remote authenticated users to inject arbitrary web script or HTML through the 'name' parameter. With a CVSS score of 3.5, it has a network attack vector and medium attack complexity, potentially leading to information compromise (impact on integrity). While the vulnerability is not listed on the KEV catalog and has no known public exploit code (Metasploit, Nuclei, ExploitDB), it has received minimal community discussion or media coverage, suggesting low active exploitation or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opstor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.