vendor:
EPESI
by:
Zeeshan Shaikh
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: EPESI
Affected Version From: 1.8.2 rev20170830
Affected Version To: 1.8.2 rev20170830
Patch Exists: Yes
Related CWE: CVE-2017-14712 to CVE-2017-14717
CPE: 2.3:a:epe.si:epe.si:1.8.2:*:*:*:*:*:*:*
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web-based
2017
Multiple Stored XSS in EPESI
Multiple Stored XSS vulnerabilities exist in EPESI, a web-based business information manager. The vulnerabilities exist in the Tasks, Phonecalls, Notes, and Alerts modules. An attacker can exploit these vulnerabilities by creating a new task, phonecall, note, or alert and entering malicious JavaScript code in the title, description, or subject fields. The malicious code will be stored in the database and executed when the user views the task, phonecall, note, or alert.
Mitigation:
The vendor has released a patch to address these vulnerabilities. Users should upgrade to the latest version of EPESI.