Description
Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.
Remediation
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-6105)
WordPress Plugin Admin Pack by SITE CASEIRO Cross-Site Scripting (1.1)
WordPress Plugin Zip Attachments Arbitrary File Download (1.4)
Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2022-42124)