CVE-2021-3539: EspoCRM Avatar Persistent XSS
Published Aug 4, 2021
·Updated
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.
Affected Software
1 affected component
EspoCRM EspoCRM<=6.1.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EspoCRMto a version that resolves this vulnerability.Fixed in 6.1.7
Event History
Aug 4, 2021
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-3539.
2
What is the severity of CVE-2021-3539?
The severity of CVE-2021-3539 is medium with a CVSS score of 5.4.
3
What is the affected software version for CVE-2021-3539?
The affected software version for CVE-2021-3539 is EspoCRM 6.1.6 and prior.
4
What is the type of vulnerability for CVE-2021-3539?
CVE-2021-3539 is a persistent (type II) cross-site scripting (XSS) vulnerability.
5
How was CVE-2021-3539 fixed?
CVE-2021-3539 was fixed in version 6.1.7 of EspoCRM.