Description
An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-3134 Vulnerability (CVE-2012-3134)
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-12459)
PHP Improper Input Validation Vulnerability (CVE-2011-4153)
WordPress Plugin Contact Form Submissions Unspecified Vulnerability (1.6.3)