Reflected Cross-Site Scripting Vulnerability in vTiger CRM by vTiger
CVE-2024-44779

9.6CRITICAL

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
29 August 2024

What is CVE-2024-44779?

A reflected cross-site scripting (XSS) vulnerability exists in the viewname parameter on the index page of vTiger CRM version 7.4.0. This vulnerability allows attackers to craft malicious payloads, which can be executed in the context of a user's browser. Successful exploitation can lead to unauthorized actions being performed on behalf of the user, potentially exposing sensitive information or enabling further attacks. It is crucial for organizations using vTiger CRM to apply necessary patches or workarounds to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-44779 : Reflected Cross-Site Scripting Vulnerability in vTiger CRM by vTiger