VYPR

Espocrm

by Espocrm

Source repositories

CVEs (46)

  • CVE-2019-14330MedJul 28, 2019
    risk 0.00cvss 6.1epss 0.02

    An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.

  • CVE-2019-14329MedJul 28, 2019
    risk 0.00cvss 6.1epss 0.02

    An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.

  • CVE-2014-7987Oct 31, 2014
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.

  • CVE-2014-7986Oct 31, 2014
    risk 0.00cvss —epss 0.03

    install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.

  • CVE-2014-7985Oct 31, 2014
    risk 0.00cvss —epss 0.05

    Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.

  • CVE-2014-8330Oct 20, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.

Page 3 of 3