Description
A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/resources/public/js/customerServe/customer.serve.js of the component Save Endpoint. This manipulation of the argument customerName causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site Scripting
Action: Monitor
AI Analysis

Impact

The vulnerability in ChangeWeDer crm allows a malicious actor to inject arbitrary JavaScript through the customerName parameter on the Save Endpoint, enabling cross‑site scripting. Attackers could execute scripts in the context of legitimate users, potentially stealing session data or defacing the web interface. The flaw is a classic reflected XSS, as defined by CWE‑79, with the parameter being processed without proper sanitization, and also involves execution of arbitrary code via CWE‑94.

Affected Systems

Affected users run the ChangeWeDer crm application, regardless of specific version, as the flaw exists in unknown code up to commit c07bd4c97141521af6475034bc58523beed51bbd. No definitive version numbers are available due to the project's rolling release model, but all installations using the current public build are potentially impacted.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate risk, while the EPSS score of less than 1% suggests low exploitation probability in the short term. The vulnerability is not yet listed in CISA’s KEV catalog, but it has been publicly disclosed and could be leveraged by attackers who can craft a request containing malicious customerName data. Because the application accepts requests from remote clients, attackers can trigger the flaw from outside the network, making it a remote XSS vector.

Generated by OpenCVE AI on September 18, 2026 at 05:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Validate and sanitize the customerName input on the server side to strip or encode any JavaScript content.
  • Enforce a robust Content Security Policy that restricts script execution to trusted sources.
  • Keep the application up‑to‑date by applying any future community patches that address this issue as soon as they become available.

Generated by OpenCVE AI on September 18, 2026 at 05:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/resources/public/js/customerServe/customer.serve.js of the component Save Endpoint. This manipulation of the argument customerName causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Title ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting
First Time appeared Changeweder
Changeweder crm
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:changeweder:crm:*:*:*:*:*:*:*:*
Vendors & Products Changeweder
Changeweder crm
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T19:19:45.506Z

Reserved: 2026-09-16T09:41:23.174Z

Link: CVE-2026-92418

cve-icon Vulnrichment

Updated: 2026-09-16T19:19:08.747Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:18:06.170

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-92418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')