Description
EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code in the body parameter during api/v1/KnowledgeBaseArticle knowledge-base record creation.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tidio Gallery Multiple Vulnerabilities (1.1)
Joomla CVE-2006-4470 Vulnerability (CVE-2006-4470)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.17)
Apache HTTP Server Numeric Errors Vulnerability (CVE-2011-3607)
WordPress Plugin Instant Images-One Click Unsplash Uploads Cross-Site Scripting (4.4.0)