VYPR
Medium severity5.4NVD Advisory· Published Sep 30, 2017· Updated May 13, 2026

CVE-2017-14923

CVE-2017-14923

Description

Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.

Affected products

1
  • cpe:2.3:a:tine20:tine_2.0:*:*:*:*:community:*:*:*
    Range: <=2017.08.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.