CVE-2019-14330: XSS
Published Jul 28, 2019
·Updated
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
Affected Software
1 affected component
EspoCRM EspoCRM<5.6.6
Remediation
Event History
Jul 28, 2019
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
Description
Frequently Asked Questions
1
What is CVE-2019-14330?
CVE-2019-14330 is an issue discovered in EspoCRM before version 5.6.6, where a Stored XSS vulnerability exists due to lack of filtration of user-supplied data in Create Case.
2
How severe is CVE-2019-14330?
CVE-2019-14330 has a severity value of 6.1, which is considered medium.
3
What is the affected software in CVE-2019-14330?
The affected software in CVE-2019-14330 is EspoCRM version up to and excluding 5.6.6.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by a malicious attacker who modifies the firstName and lastName fields in Create Case to contain JavaScript code.
5
Is there a fix available for CVE-2019-14330?
Yes, a fix is available in EspoCRM version 5.6.6.