Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc2f-4vmr-c74r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page"

Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page"

EPSS

Процентиль: 50%
0.00264
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
почти 5 лет назад

Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page"

EPSS

Процентиль: 50%
0.00264
Низкий

Дефекты

CWE-79