Description
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
Remediation
References
Related Vulnerabilities
MySQL CVE-2016-0651 Vulnerability (CVE-2016-0651)
Joomla Incorrect Authorization Vulnerability (CVE-2010-1435)
WordPress Plugin Simple File List Arbitrary File Upload (4.2.2)
MediaWiki Improper Input Validation Vulnerability (CVE-2017-8811)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-3628)