Description
Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page"
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-13867 | Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page" |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T14:22:25.554Z
Reserved: 2020-08-13T00:00:00.000Z
Link: CVE-2020-21088
No data.
Status : Modified
Published: 2021-04-14T14:15:13.210
Modified: 2024-11-21T05:12:25.627
Link: CVE-2020-21088
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD