Description
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.
Remediation
References
Related Vulnerabilities
WordPress Plugin Rise Blocks-A Complete Gutenberg Page Builder Unspecified Vulnerability (1.0.0)
WordPress Plugin ACF to REST API Information Disclosure (3.2.0)
Joomla! Core 3.6.0 Cross-Site Request Forgery (3.6.0)
MySQL CVE-2021-35591 Vulnerability (CVE-2021-35591)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7854)