Description
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
Published: 2026-06-03
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected or stored cross‑site scripting flaw that allows an attacker to embed malicious scripts within the Social Media link fields of a user’s profile. When another user views the profile, the embedded script executes in the victim’s browser, which can be used to steal session cookies, hijack user accounts, or perform actions on behalf of the victim. Because the attacker can manipulate the content that is rendered by the target’s browser, the impact ranges from data theft to complete privilege escalation within the system.

Affected Systems

RockRMS, the common open‑source customer relationship management platform, is affected in all releases from version 16.13 up to and including 17.7.0. The issue arises in the user profile module, specifically where Social Media link URLs are displayed without proper sanitization. Administrators should monitor for subsequent releases that address this flaw, as no specific fixed version is identified in the data.

Risk and Exploitability

The CVSS score is 9, and no EPSS score has been reported, indicating that there is currently no widespread evidence of exploitation. Nonetheless, XSS vulnerabilities typically carry high severity because they can be abused to hijack user sessions or force administrative actions. The exploitation path requires the attacker to first inject a malicious payload into a Social Media link and then persuade or trick a victim to view the compromised profile. The vulnerability is listed in no KEV catalog, so it is not confirmed as part of known exploits, but administrators should view it as a high‑risk issue pending an update. The likely attack vector involves an attacker injecting malicious content into the Social Media link field of a user profile that is rendered to other users, which is inferred from the description that the flaw is in Social Media links.

Generated by OpenCVE AI on June 3, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a newer RockRMS release that includes the fix for Social Media link sanitization, once it is available.
  • Temporarily disable or restrict the Social Media link functionality in user profiles to prevent script injection.
  • Manually review existing user profiles for injected malicious code, and restrict editing rights for that field to trusted administrators.
  • Configure a web application firewall or set a Content Security Policy to block execution of inline scripts.

Generated by OpenCVE AI on June 3, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sparkdevnetwork
Sparkdevnetwork rock Rms
Vendors & Products Sparkdevnetwork
Sparkdevnetwork rock Rms

Wed, 03 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Social Media Links in RockRMS User Profiles Leading to Privilege Escalation

Wed, 03 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Social Media Links in RockRMS User Profiles Leading to Privilege Escalation
Weaknesses CWE-79

Wed, 03 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Description RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
References

Subscriptions

Sparkdevnetwork Rock Rms
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-03T18:20:35.787Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36748

cve-icon Vulnrichment

Updated: 2026-06-03T18:18:46.625Z

cve-icon NVD

Status : Deferred

Published: 2026-06-03T16:16:29.000

Modified: 2026-06-04T15:41:35.193

Link: CVE-2026-36748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:12:39Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')