PT-2019-13746 · Espocrm · Espocrm

Gauravnarwani97

·

Publicado

2019-08-05

·

Atualizado

2019-08-09

·

CVE-2019-14548

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EspoCRM versions prior to 5.6.9
Description An issue allows stored XSS in the body of an Article, which is executed when a victim opens articles received through mail. The Article can be formed by an attacker using the Knowledge Base feature. The attacker could inject malicious JavaScript inside the body of the article to steal victims' cookies, thus compromising their accounts.
Recommendations For versions prior to 5.6.9, update to version 5.6.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the Knowledge Base feature to minimize the risk of exploitation. Avoid using the Knowledge Base feature to form Articles until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-14548

Produtos afetados

Espocrm