Unrated severityNVD Advisory· Published Aug 4, 2021· Updated Sep 16, 2024
EspoCRM Avatar Persistent XSS
CVE-2021-3539
Description
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.