Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2019-13643
Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. The stored payload can then be triggered by clicking a malicious link on the Notifications page.
0
Attacker Value
Unknown
CVE-2018-17302
Disclosure Date: September 21, 2018 (last updated November 08, 2023)
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
0
Attacker Value
Unknown
CVE-2018-17301
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
0
Attacker Value
Unknown
CVE-2014-7987
Disclosure Date: October 31, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.
0
Attacker Value
Unknown
CVE-2014-7985
Disclosure Date: October 31, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.
0
Attacker Value
Unknown
CVE-2014-7986
Disclosure Date: October 31, 2014 (last updated October 05, 2023)
install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.
0
Attacker Value
Unknown
CVE-2014-8330
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.
0