Reflected XSS in Vtiger CRM by Vtiger
CVE-2020-19362
6.1MEDIUM
What is CVE-2020-19362?
A reflected cross-site scripting (XSS) vulnerability exists in Vtiger CRM version 7.2.0, specifically in the 'view' parameter of the vtigercrm/index.php endpoint. This flaw can be exploited by an attacker to execute unauthorized scripts in the context of a user's session. When a user clicks on a specially crafted link or visits a malicious webpage, the attacker's JavaScript code could perform unintended actions on their behalf, leading to potential data theft or further exploitation.