Description
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code in the body parameter during api/v1/KnowledgeBaseArticle knowledge-base record creation.
Remediation
References
Related Vulnerabilities
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-9049)
WordPress Plugin WordPress Slider Block Gutenslider Cross-Site Scripting (5.1.5)
WordPress Plugin WPCOM Member Malicious Code (1.3.16)
MySQL CVE-2019-2580 Vulnerability (CVE-2019-2580)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1860)