Description
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-6474 Vulnerability (CVE-2014-6474)
WordPress Plugin FV Flowplayer Video Player SQL Injection (7.5.15.727)
WordPress Plugin YITH WooCommerce Subscription Security Bypass (1.3.4)
WordPress Other Vulnerability (CVE-2004-1584)
WordPress Plugin Product Catalog Multiple Vulnerabilities (3.1.2)