Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page"
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-04-14T13:49:44
Updated: 2024-08-04T14:22:25.554Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-21088
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-04-14T14:15:13.210
Modified: 2024-11-21T05:12:25.627
Link: CVE-2020-21088
Redhat
No data.