Impact
The vulnerability in ChangeWeDer crm allows a malicious actor to inject arbitrary JavaScript through the customerName parameter on the Save Endpoint, enabling cross‑site scripting. Attackers could execute scripts in the context of legitimate users, potentially stealing session data or defacing the web interface. The flaw is a classic reflected XSS, as defined by CWE‑79, with the parameter being processed without proper sanitization, and also involves execution of arbitrary code via CWE‑94.
Affected Systems
Affected users run the ChangeWeDer crm application, regardless of specific version, as the flaw exists in unknown code up to commit c07bd4c97141521af6475034bc58523beed51bbd. No definitive version numbers are available due to the project's rolling release model, but all installations using the current public build are potentially impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk, while the EPSS score of less than 1% suggests low exploitation probability in the short term. The vulnerability is not yet listed in CISA’s KEV catalog, but it has been publicly disclosed and could be leveraged by attackers who can craft a request containing malicious customerName data. Because the application accepts requests from remote clients, attackers can trigger the flaw from outside the network, making it a remote XSS vector.
OpenCVE Enrichment