Description
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Digg Digg Cross-Site Request Forgery (5.3.4)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5492)
WordPress Plugin Chained Quiz Cross-Site Scripting (1.2.7)
Jboss EAP Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2011-2487)
Oracle Application Server CVE-2008-5438 Vulnerability (CVE-2008-5438)