Stored XSS Vulnerability in EspoCRM by EspoCRM
CVE-2019-14349

6.1MEDIUM

Key Information:

Vendor

Espocrm

Status
Vendor
CVE Published:
28 July 2019

What is CVE-2019-14349?

EspoCRM version 5.6.4 has a vulnerability that allows stored XSS attacks due to insufficient filtering of user-supplied data in the document storage functionality. An attacker can exploit this vulnerability by uploading a maliciously crafted file containing JavaScript in its name. When users view profiles associated with the crafted document, the embedded JavaScript code executes, leading to potential session hijacking or data compromise.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.