ZeroHour

CVE-2020-21088

PoC ×2
CVSS 3.1
4.8 medium
EPSS
<1%p53
Published
()
Modified
Description

Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page"

Vendors
x2engine
Products
x2crm
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.