PT-2019-13747 · Espocrm · Espocrm

Gauravnarwani97

·

Published

2019-08-05

·

Updated

2019-08-09

·

CVE-2019-14549

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EsponCRM versions prior to 5.6.9
Description The issue allows a malicious user to inject JavaScript in the title and breadcrumb of a newly formed entity, which can lead to stored XSS execution. This can result in the theft of user cookies when someone visits a publicly accessible link.
Recommendations For versions prior to 5.6.9, update to version 5.6.9 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14549

Affected Products

Espocrm