ID
VAR-201104-0356
TITLE
vtiger CRM 'vtigerservice.php' Cross Site Scripting Vulnerability
Trust: 0.3
sources:
BID: 47267
DESCRIPTION
vtiger CRM is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. vtiger CRM 5.2.1 is vulnerable; other versions may also be affected.
Trust: 0.3
sources:
BID: 47267
AFFECTED PRODUCTS
vendor: | vtiger | model: | crm | scope: | eq | version: | 5.2.1 | Trust: 0.3 |
sources:
BID: 47267
THREAT TYPE
network
Trust: 0.3
sources:
BID: 47267
TYPE
Input Validation Error
Trust: 0.3
sources:
BID: 47267
EXTERNAL IDS
db: | BID | id: | 47267 | Trust: 0.3 |
sources:
BID: 47267
REFERENCES
url: | http://www.vtiger.com/ | Trust: 0.3 |
sources:
BID: 47267
CREDITS
AutoSec Tools
Trust: 0.3
sources:
BID: 47267
SOURCES
db: | BID | id: | 47267 |
LAST UPDATE DATE
2022-05-17T02:09:59.305000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 47267 | date: | 2011-04-07T00:00:00 |
SOURCES RELEASE DATE
db: | BID | id: | 47267 | date: | 2011-04-07T00:00:00 |