PoC Index

CVE-2022-38845

MEDIUM 6.1EPSS 0.7%

Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.67% chance of exploitation in the next 30 days, 50th percentile
Published
2022-09-16
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related