Unrated severityNVD Advisory· Published Jul 18, 2019· Updated Aug 4, 2024
CVE-2019-13643
CVE-2019-13643
Description
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. The stored payload can then be triggered by clicking a malicious link on the Notifications page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- EspoCRM/EspoCRMdescription
Patches
Vulnerability mechanics
References
1- github.com/espocrm/espocrm/issues/1349mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.