CVE-2019-14331: XSS
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14331?
CVE-2019-14331 is a vulnerability discovered in EspoCRM before version 5.6.6 that allows for stored XSS attacks due to lack of filtration of user-supplied data in the Create User feature.
What is the severity of CVE-2019-14331?
The severity of CVE-2019-14331 is medium, with a CVSS score of 6.1.
How does CVE-2019-14331 affect EspoCRM?
CVE-2019-14331 affects EspoCRM versions prior to 5.6.6, allowing malicious attackers to execute stored XSS attacks by modifying the firstName and lastName fields.
Is there a fix available for CVE-2019-14331?
Yes, a fix for CVE-2019-14331 is available in EspoCRM version 5.6.6.
Where can I find more information about CVE-2019-14331?
You can find more information about CVE-2019-14331 at the following references: [1] http://www.cinquino.eu/EspoCRM.htm [2] https://github.com/espocrm/espocrm/commit/4ab7d19776011288b875abd3eef1e1f6f75289e2 [3] https://github.com/espocrm/espocrm/compare/5.6.5...5.6.6