Description
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
Remediation
References
Related Vulnerabilities
Perl Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2018-12015)
WordPress Plugin Wise Chat Open Redirect (2.6.3)
Oracle Database Server CVE-2018-2841 Vulnerability (CVE-2018-2841)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8005)