CVE-2014-8330: XSS
Published Oct 20, 2014
·Updated
Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.
Affected Software
1 affected component
EspoCRM EspoCRM
Event History
Oct 20, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8330?
CVE-2014-8330 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2014-8330?
To fix CVE-2014-8330, update to the latest version of EspoCRM that resolves this XSS vulnerability.
3
Who is affected by CVE-2014-8330?
CVE-2014-8330 affects remote authenticated users of EspoCRM who can inject scripts via the Name field.
4
What type of vulnerability is CVE-2014-8330?
CVE-2014-8330 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2014-8330 be exploited by unauthenticated users?
No, CVE-2014-8330 can only be exploited by authenticated users who have access to create new accounts in EspoCRM.