ID

VAR-201104-0356


TITLE

vtiger CRM 'vtigerservice.php' Cross Site Scripting Vulnerability

Trust: 0.3

sources: BID: 47267

DESCRIPTION

vtiger CRM is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. vtiger CRM 5.2.1 is vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 47267

AFFECTED PRODUCTS

vendor:vtigermodel:crmscope:eqversion:5.2.1

Trust: 0.3

sources: BID: 47267

THREAT TYPE

network

Trust: 0.3

sources: BID: 47267

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 47267

EXTERNAL IDS

db:BIDid:47267

Trust: 0.3

sources: BID: 47267

REFERENCES

url:http://www.vtiger.com/

Trust: 0.3

sources: BID: 47267

CREDITS

AutoSec Tools

Trust: 0.3

sources: BID: 47267

SOURCES

db:BIDid:47267

LAST UPDATE DATE

2022-05-17T02:09:59.305000+00:00


SOURCES UPDATE DATE

db:BIDid:47267date:2011-04-07T00:00:00

SOURCES RELEASE DATE

db:BIDid:47267date:2011-04-07T00:00:00