PoC Index

CVE-2019-14548

MEDIUM 5.4EPSS 1.1%

An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base feature in the tab list. The attacker could inject malicious JavaScript inside the body of the article, thus helping him steal victims' cookies (hence compromising their accounts).

CVSS v3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
1.08% chance of exploitation in the next 30 days, 63th percentile
Published
2019-08-05
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related