HTML Injection Vulnerability in Vtiger CRM by Vtiger
CVE-2024-48119

5.4MEDIUM

Key Information:

Vendor

Vtiger

Vendor
CVE Published:
14 October 2024

What is CVE-2024-48119?

Vtiger CRM v8.2.0 is susceptible to an HTML Injection vulnerability within the module parameter. This allows authenticated users to inject arbitrary HTML code, potentially compromising the application's integrity and user data. Proper validation and sanitization practices should be implemented to mitigate the risk associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2024-48119 : HTML Injection Vulnerability in Vtiger CRM by Vtiger