Reflected XSS Vulnerability in EspoCRM by Espo Technologies
CVE-2018-17301

5.4MEDIUM

Key Information:

Vendor

Espocrm

Status
Vendor
CVE Published:
21 September 2018

What is CVE-2018-17301?

A reflected XSS vulnerability was discovered in the search functionality of EspoCRM version 5.3.6. Specifically, the issue resides in the 'name-field.tpl' file, which can be exploited via the /#Account endpoint. When crafted malicious requests are made, an attacker can inject arbitrary JavaScript, potentially leading to data theft or session hijacking, emphasizing the need for vigilance and patches to safeguard users from such security risks.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.