Reflected Cross-Site Scripting Vulnerability in vTiger CRM by vTiger
CVE-2024-44778

9.6CRITICAL

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
29 August 2024

What is CVE-2024-44778?

A reflected cross-site scripting vulnerability exists within the parent parameter of the index page in vTiger CRM 7.4.0, enabling attackers to inject a crafted payload. This exploitation allows the execution of arbitrary code within the context of a user's browser, which can lead to unauthorized actions and data leakage. Organizations using this version of vTiger CRM should prioritize evaluating their security posture in response to this vulnerability to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.