Reflected XSS Vulnerability in vtiger CRM by vtiger
CVE-2018-8047

6.1MEDIUM

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
6 June 2019

What is CVE-2018-8047?

vtiger CRM 7.0.1 is vulnerable to reflected Cross-Site Scripting (XSS), allowing attackers to inject malicious scripts through specific HTTP parameters. This vulnerability can be exploited via the index.php page when accessing the Contacts module, potentially compromising user data and enabling further attacks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-8047 : Reflected XSS Vulnerability in vtiger CRM by vtiger