CVE-2014-7987: XSS
Published Oct 31, 2014
·Updated
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.
Affected Software
1 affected component
EspoCRM EspoCRM<=2.5.2
Remediation
Patch Available
Event History
Oct 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7987?
The severity of CVE-2014-7987 is considered medium as it allows for cross-site scripting attacks that can compromise user accounts and data.
2
How do I fix CVE-2014-7987?
To fix CVE-2014-7987, upgrade EspoCRM to version 2.6.0 or later where this vulnerability is addressed.
3
What type of vulnerability is CVE-2014-7987?
CVE-2014-7987 is a cross-site scripting (XSS) vulnerability that affects EspoCRM.
4
What software versions are affected by CVE-2014-7987?
EspoCRM versions prior to 2.6.0, specifically up to and including version 2.5.2, are affected by CVE-2014-7987.
5
Who can exploit CVE-2014-7987?
Remote attackers can exploit CVE-2014-7987 to inject arbitrary web scripts or HTML into the affected EspoCRM application.