Vulnerabilities > Espocrm
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-09-21 | CVE-2018-17302 | Cross-site Scripting vulnerability in Espocrm 5.3.6 Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message. | 5.4 |
2018-09-21 | CVE-2018-17301 | Cross-site Scripting vulnerability in Espocrm 5.3.6 Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel. | 5.4 |