← Vulnerability feed

Vulnerability record · CVE-2014-4301 · published 18 June 2014

CVE-2014-4301: Ajenti cross-site scripting vulnerability

Ajenti · Ajenti

Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.

4.3 CVSS 2.0 Medium EPSS 2.3% · top 17.4% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-4301 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-25066Ajenti improper privilege management vulnerabilityA vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipul…EPSS 5.4%8.8CVE-2018-1000082Ajenti cross-site request forgery vulnerabilityAjenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the serv…EPSS 1.3%8.1CVE-2026-27975Ajenti improper access control vulnerabilityAjenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbit…EPSS 0.67%7.5CVE-2018-1000126Ajenti information exposure vulnerabilityAjenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as we…EPSS 1.6%7.5CVE-2018-1000081Ajenti improper input validation vulnerabilityAjenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This a…EPSS 1.1%7.2CVE-2026-35175Ajenti missing authorization vulnerabilityAjenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugin authentication method) coul…EPSS 0.38%6.5CVE-2018-1000080Ajenti incorrect permission assignment vulnerabilityAjenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a …EPSS 0.84%5.3CVE-2018-1000083Ajenti path traversal vulnerabilityAjenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of th…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2014-4301), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.