Stored XSS Vulnerability in EspoCRM by EspoCRM
CVE-2019-14349
6.1MEDIUM
What is CVE-2019-14349?
EspoCRM version 5.6.4 has a vulnerability that allows stored XSS attacks due to insufficient filtering of user-supplied data in the document storage functionality. An attacker can exploit this vulnerability by uploading a maliciously crafted file containing JavaScript in its name. When users view profiles associated with the crafted document, the embedded JavaScript code executes, leading to potential session hijacking or data compromise.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved