ZeroHour

CVE-2024-54687

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p30
Published
()
Modified
Description

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

Vendors
vtiger
Products
vtiger crm
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.