Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.
References
Link | Resource |
---|---|
https://okankurtulus.com.tr/2024/09/12/vtiger-crm-v8-2-0-html-injection-authenticated/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-10-14 14:15
Updated : 2024-10-30 14:32
NVD link : CVE-2024-48119
Mitre link : CVE-2024-48119
CVE.ORG link : CVE-2024-48119
JSON object : View
Products Affected
vtiger
- vtiger_crm
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')