Stored Cross-Site Scripting Flaw in Energy CRM by Status Tracker Ltd
CVE-2025-40640

5.1MEDIUM

Key Information:

Vendor
CVE Published:
10 October 2025

What is CVE-2025-40640?

A stored Cross-Site Scripting (XSS) vulnerability exists in Energy CRM v2025, developed by Status Tracker Ltd, which results from inadequate validation of user inputs. Specifically, the vulnerability arises when a POST request is made to "/crm/create_invoice_submit.php" with the "customerName_0" parameter. Attackers can exploit this flaw to send malicious requests to authenticated users, potentially allowing them to steal cookie session details, which can be used for unauthorized access. It is crucial for users of Energy CRM v2025 to implement appropriate input validation and security measures to safeguard against such attacks.

Affected Version(s)

Energy CRM version 2025

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Intilangelo
.
CVE-2025-40640 : Stored Cross-Site Scripting Flaw in Energy CRM by Status Tracker Ltd