### [CVE-2019-14668](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14668)



### Description
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link.
### POC
#### Reference
- https://github.com/firefly-iii/firefly-iii/issues/2364
#### Github
No PoCs found on GitHub currently.