Description
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Fast Velocity Minify Information Disclosure (2.7.6)
WordPress Plugin Product Catalog SQL Injection (4.2.2)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5730)
MediaWiki Improper Authentication Vulnerability (CVE-2021-30158)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-33331)