CVE-2019-14550: XSS
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list feature, which would fire when a user clicks on the Edit Dashboard button, thus helping him steal victims' cookies (hence compromising their accounts).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14550?
CVE-2019-14550 is a vulnerability discovered in EspoCRM before version 5.6.9 that allows for stored cross-site scripting (XSS) attacks.
How severe is CVE-2019-14550?
CVE-2019-14550 has a severity rating of 5.4, which is considered medium.
How does CVE-2019-14550 affect EspoCRM?
CVE-2019-14550 affects EspoCRM versions up to 5.6.9.
How can an attacker exploit CVE-2019-14550?
An attacker can exploit CVE-2019-14550 by loading malicious JavaScript into the add tab list feature and tricking a user into clicking on the Edit Dashboard button.
Is there a fix available for CVE-2019-14550?
Yes, a fix for CVE-2019-14550 is available in EspoCRM version 5.6.9 and later.