Reflected Cross-Site Scripting Vulnerability in vTiger CRM by vTiger
CVE-2024-44777

9.6CRITICAL

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
29 August 2024

What is CVE-2024-44777?

A reflected cross-site scripting vulnerability exists in the tag parameter of the index page of vTiger CRM 7.4.0. This security flaw permits attackers to exploit the system by injecting a carefully crafted payload that can execute arbitrary code within the context of an unsuspecting user's browser. This can lead to unauthorized actions, data theft, and compromise of sensitive user information. It is crucial for users and administrators of vTiger CRM to implement security updates and best practices to mitigate the risks associated with such vulnerabilities.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-44777 : Reflected Cross-Site Scripting Vulnerability in vTiger CRM by vTiger