### [CVE-2019-14670](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14670)



### Description
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.
### POC
#### Reference
- https://github.com/firefly-iii/firefly-iii/issues/2365
#### Github
No PoCs found on GitHub currently.