Description
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Calls to Action Multiple Vulnerabilities (2.3.7)
WordPress Plugin Captcha Backdoor (4.4.4)
MySQL Out-of-bounds Write Vulnerability (CVE-2020-15358)
WordPress Plugin RokMicroNews Multiple Vulnerabilities (1.5)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-4753)