CVE-2019-14329: XSS
Published Jul 28, 2019
·Updated
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.
Affected Software
1 affected component
EspoCRM EspoCRM<5.6.6
Remediation
Event History
Jul 28, 2019
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in EspoCRM?
The vulnerability ID for this issue in EspoCRM is CVE-2019-14329.
2
What is the severity of CVE-2019-14329?
The severity of CVE-2019-14329 is medium with a severity value of 6.1.
3
What is the affected version of EspoCRM?
The affected version of EspoCRM is up to exclusive version 5.6.6.
4
What is the vulnerability description for CVE-2019-14329?
CVE-2019-14329 is a stored XSS vulnerability in EspoCRM before 5.6.6, caused by a lack of filtration of user-supplied data in Create Task, allowing a malicious attacker to modify the parameter name and inject JavaScript code.
5
How can I fix CVE-2019-14329 in EspoCRM?
To fix CVE-2019-14329 in EspoCRM, upgrade to version 5.6.6 or later.