CVE-2019-14350: XSS
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code in the body parameter during api/v1/KnowledgeBaseArticle knowledge-base record creation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14350?
CVE-2019-14350 is a vulnerability that affects EspoCRM version 5.6.4, allowing for stored XSS attacks in the Knowledge base.
How does CVE-2019-14350 work?
CVE-2019-14350 works by not filtering user-supplied data in the Knowledge base, allowing a malicious attacker to inject JavaScript code during the creation of a KnowledgeBaseArticle.
What is the severity of CVE-2019-14350?
The severity of CVE-2019-14350 is medium with a CVSS score of 6.1.
How can EspoCRM 5.6.4 be affected by CVE-2019-14350?
EspoCRM version 5.6.4 is vulnerable to CVE-2019-14350.
How can I fix CVE-2019-14350?
To fix CVE-2019-14350, update EspoCRM to a version that includes a patch for this vulnerability.