Reflected XSS in Vtiger CRM by Vtiger
CVE-2020-19362

6.1MEDIUM

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
20 January 2021

What is CVE-2020-19362?

A reflected cross-site scripting (XSS) vulnerability exists in Vtiger CRM version 7.2.0, specifically in the 'view' parameter of the vtigercrm/index.php endpoint. This flaw can be exploited by an attacker to execute unauthorized scripts in the context of a user's session. When a user clicks on a specially crafted link or visits a malicious webpage, the attacker's JavaScript code could perform unintended actions on their behalf, leading to potential data theft or further exploitation.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-19362 : Reflected XSS in Vtiger CRM by Vtiger