Back to Database
Status published
Medium
CVE-2018-17302
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a...
Vulnerability Description
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-17302
Credits & Attribution
No credits recorded in the NVD database.
References
More from espocrm
View All →CVE-2025-59428
EspoCRM allows arbitrary user creation via stored SVG injection and CSRF
Medium
5.4
CVE-2025-52892
EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache
Medium
4.5
CVE-2025-52575
EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements
Medium
6.5
CVE-2025-32789
EspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting Function
Low
3.1
CVE-2025-32390
EspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover
High
7
Affected Vendor
espocrm
View all reports →Affected Software
espocrm
Vulnerable Versions:
5.3.6
Timeline
Official Publish:
September 21st, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.