Description
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code in the body parameter during api/v1/KnowledgeBaseArticle knowledge-base record creation.
Remediation
References
Related Vulnerabilities
WordPress Plugin Events Manager Extended Multiple HTML Injection Vulnerabilities (3.1.2)
PHP Other Vulnerability (CVE-2020-7066)
Liferay Portal CVE-2024-25148 Vulnerability (CVE-2024-25148)
WordPress Plugin Human Presence Cross-Site Scripting (2.0.8)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.3.29)