Description
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
Remediation
References
Related Vulnerabilities
b2evolution URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-22840)
Joomla! Core 1.0.x Remote File Inclusion (1.0.11 - 1.0.14)
WordPress Plugin WordPress Backup and Migrate-Backup Guard Unspecified Vulnerability (1.0.6)
WordPress Plugin Widgets for SiteOrigin Security Bypass (1.4.2)
Oracle Application Server Other Vulnerability (CVE-2005-3446)