Loading
Cross-site scripting (XSS) vulnerability in Telerik UI for ASP.NET AJAX RadEditor control 2014.1.403.35, 2009.3.1208.20, and other versions allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.
Use CWE-79, Telerik vendor hub and Asp.Net Ajax Radeditor Control product page to widen CVE-2014-4958 into its surrounding weakness, vendor, and product context.