Description
An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Cross-Site Scripting (4.0.2)
WordPress Plugin Simple Mail Address Encoder Cross-Site Scripting (1.6.1)
WordPress Plugin CBX Petition for WordPress SQL Injection (1.0.3)
WordPress Plugin LayerSlider Cross-Site Request Forgery (4.6.1)
Jboss Deserialization of Untrusted Data Vulnerability (CVE-2017-7504)