CVE-2019-13643
Last modified
CVE-2019-13643 is a vulnerability of currently unknown severity. Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source code into the target pages. The attack begins by storing a new stream message containing an XSS payload. The stored payload can then be triggered by clicking a malicious link on the Notifications page.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Espocrm | Espocrm | < 5.6.4 |
References
- https://github.com/espocrm/espocrm/issues/1349Exploit, Third Party Advisory
- https://github.com/espocrm/espocrm/milestone/64?closed=1Third Party Advisory
- https://github.com/espocrm/espocrm/issues/1349Exploit, Third Party Advisory
- https://github.com/espocrm/espocrm/milestone/64?closed=1Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13643?
How severe is CVE-2019-13643?
How do I fix CVE-2019-13643?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13635The WP Fastest Cache plugin through 0.8.9.5 for WordPress al…
- CVE-2019-13636In GNU patch through 2.7.6, the following of symlinks is mis…
- CVE-2019-13637In LogMeIn join.me before 3.16.0.5505, an attacker could exe…
- CVE-2019-13638GNU patch through 2.7.6 is vulnerable to OS shell command in…
- CVE-2019-1364An elevation of privilege vulnerability exists in Windows wh…7.8
- CVE-2019-13640In qBittorrent before 4.1.7, the function Application::runEx…
- CVE-2019-13644Firefly III before 4.7.17.1 is vulnerable to stored XSS due …5.4
- CVE-2019-13645Firefly III before 4.7.17.3 is vulnerable to stored XSS due …
- CVE-2019-13646Firefly III before 4.7.17.3 is vulnerable to reflected XSS d…
- CVE-2019-13647Firefly III before 4.7.17.3 is vulnerable to stored XSS due …
- CVE-2019-13648In the Linux kernel through 5.2.1 on the powerpc platform, w…
- CVE-2019-13649TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n …9.8
Are you affected by CVE-2019-13643?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
