ZeroHour

CVE-2020-21087

PoC
CVSS 3.1
6.1 medium
EPSS
1%p70
Published
()
Modified
Description

Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web script or HTML via the "New Name" field of the "Rename a Module" tool.

Vendors
x2engine
Products
x2crm
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.