First published: Fri Oct 31 2014(Updated: )
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EspoCRM | <=2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-7987 is considered medium as it allows for cross-site scripting attacks that can compromise user accounts and data.
To fix CVE-2014-7987, upgrade EspoCRM to version 2.6.0 or later where this vulnerability is addressed.
CVE-2014-7987 is a cross-site scripting (XSS) vulnerability that affects EspoCRM.
EspoCRM versions prior to 2.6.0, specifically up to and including version 2.5.2, are affected by CVE-2014-7987.
Remote attackers can exploit CVE-2014-7987 to inject arbitrary web scripts or HTML into the affected EspoCRM application.