Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown

CVE-2019-13643

Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. The stored payload can then be triggered by clicking a malicious link on the Notifications page.
0
Attacker Value
Unknown

CVE-2018-17302

Disclosure Date: September 21, 2018 (last updated November 08, 2023)
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
0
Attacker Value
Unknown

CVE-2018-17301

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
0
Attacker Value
Unknown

CVE-2014-7987

Disclosure Date: October 31, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.
0
Attacker Value
Unknown

CVE-2014-7985

Disclosure Date: October 31, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.
0
Attacker Value
Unknown

CVE-2014-7986

Disclosure Date: October 31, 2014 (last updated October 05, 2023)
install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.
0
Attacker Value
Unknown

CVE-2014-8330

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.
0