CVE-2019-14546
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his email signature, which fires when the victim replies or forwards the mail, thus helping him steal victims' cookies (hence compromising their accounts).
- Affected products
- Espocrm
- Espocrm
- < 5.6.9
- Fix
- Available
- CVSS 3.0
- 5.4 MEDIUM
- EPSS
- 1.1% (62th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2019-08-05
CVE-2019-14546 at NVD
No indexed exploits for CVE-2019-14546 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-14546 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.