Stored XSS Vulnerability in Firefly III by Firefly III
CVE-2019-14670
5.4MEDIUM
What is CVE-2019-14670?
The Firefly III application version 4.7.17.3 is exposed to a stored XSS vulnerability due to insufficient validation of user input in the bill name field. This flaw allows an attacker to inject malicious JavaScript code, which is executed when a user creates a rule from the bill. Proper input sanitization measures are crucial to prevent such exploitation, ensuring the safety and integrity of user data.
