Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s browser via sending crafted csv file containing malicious JavaScript to authenticated user. Any authenticated user importing the crafted CSV file may end up running the malicious JavaScripting in the browser.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-09-16T13:24:36
Updated: 2024-08-03T11:02:14.615Z
Reserved: 2022-08-29T00:00:00
Link: CVE-2022-38845
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-16T14:15:09.630
Modified: 2024-11-21T07:17:10.000
Link: CVE-2022-38845
Redhat
No data.