Stored XSS Vulnerability in EspoCRM Product by EspoCRM
CVE-2019-14549
5.4MEDIUM
What is CVE-2019-14549?
A vulnerability in EspoCRM allows for stored Cross-Site Scripting (XSS), enabling an attacker to inject malicious JavaScript into the title and breadcrumb fields of a newly created entity. When other users access this publicly available entity, their cookies can be compromised. This exposes sensitive user data and can lead to further exploitation of the application.