Cross-Site Scripting Vulnerability in PHPGurukul Small CRM
CVE-2024-48170

Currently unrated

Key Information:

Vendor
PHPGurukul
Status
Vendor
CVE Published:
10 February 2025

Summary

The PHPGurukul Small CRM 3.0 is susceptible to a Cross-Site Scripting (XSS) attack, allowing an attacker to execute arbitrary JavaScript code by injecting a malicious payload into the 'name' field through the profile.php page. This vulnerability poses significant risks to user data and can lead to unauthorized access, session hijacking, and compromise browsers, highlighting the critical need for updating and validating user input to safeguard against such threats.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.