ZeroHour

CVE-2019-13643

PoC
CVSS 3.0
6.1 medium
EPSS
1%p65
Published
()
Modified
Description

Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. The stored payload can then be triggered by clicking a malicious link on the Notifications page.

Vendors
espocrm
Products
espocrm
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.