{"id":"CVE-2019-14672","details":"Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show page.","modified":"2026-07-08T20:30:56.482540Z","published":"2019-08-05T20:15:12.297Z","references":[{"type":"FIX","url":"https://github.com/firefly-iii/firefly-iii/commit/8717f469b10e9f7e1547c6f70f7d24e1359d28d4"},{"type":"EVIDENCE","url":"https://github.com/firefly-iii/firefly-iii/issues/2370"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/firefly-iii/firefly-iii","events":[{"introduced":"ece0c99dbb4fbd6437e98d842730339c8030f517"},{"last_affected":"ece0c99dbb4fbd6437e98d842730339c8030f517"},{"fixed":"8717f469b10e9f7e1547c6f70f7d24e1359d28d4"}],"database_specific":{"cpe":"cpe:2.3:a:firefly-iii:firefly_iii:4.7.17.5:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.7.17.5"},{"last_affected":"4.7.17.5"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["4.7.17.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14672.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}