Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49440 | A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 17 Sep 2024 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:perfexcrm:perfex_crm:3.1.6:*:*:*:*:*:*:* |
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perfexcrm
Perfexcrm perfex Crm |
|
| CPEs | cpe:2.3:a:perfexcrm:perfex_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Perfexcrm
Perfexcrm perfex Crm |
|
| Metrics |
ssvc
|
Sun, 15 Sep 2024 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. | |
| Title | Perfex CRM Parameter Clients.php cross site scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-09-16T20:09:42.132Z
Reserved: 2024-09-14T08:06:29.683Z
Link: CVE-2024-8867
Updated: 2024-09-16T20:09:37.167Z
Status : Analyzed
Published: 2024-09-15T03:15:01.840
Modified: 2024-09-17T10:55:05.913
Link: CVE-2024-8867
No data.
OpenCVE Enrichment
No data.
EUVD