Stored Cross-Site Scripting Flaw in Energy CRM by Status Tracker Ltd
CVE-2025-40640
5.1MEDIUM
What is CVE-2025-40640?
A stored Cross-Site Scripting (XSS) vulnerability exists in Energy CRM v2025, developed by Status Tracker Ltd, which results from inadequate validation of user inputs. Specifically, the vulnerability arises when a POST request is made to "/crm/create_invoice_submit.php" with the "customerName_0" parameter. Attackers can exploit this flaw to send malicious requests to authenticated users, potentially allowing them to steal cookie session details, which can be used for unauthorized access. It is crucial for users of Energy CRM v2025 to implement appropriate input validation and security measures to safeguard against such attacks.
Affected Version(s)
Energy CRM version 2025