ZeroHour

CVE-2021-27288

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p58
Published
()
Modified
Description

Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "Comment" field in "/profile/activity" page.

Vendors
x2engine
Products
x2crm
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.