CVE-2014-1223: Telligent Evolution

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in controlpanel/loading.aspx in Telligent Evolution before 6.1.19.36103, 7.x before 7.1.12.36162, 7.5.x, and 7.6.x before 7.6.7.36651 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.

Affected products

  • Telligent Evolution: from 6.1, before 6.1.19.36103 (fixed in 6.1.19.36103); from 7.1, before 7.1.12.36162 (fixed in 7.1.12.36162); from 7.5, up to and including 7.5.0.32466; from 7.6, before 7.6.7.36651 (fixed in 7.6.7.36651)

Published 2014-02-27. Last modified 2026-06-17.