ID

VAR-201906-1070


CVE

CVE-2018-8047


TITLE

vtiger CRM Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2018-015583

DESCRIPTION

vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter). vtiger CRM Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. Vtiger CRM is a customer relationship management system (CRM) based on SugarCRM developed by American Vtiger Company. The management system provides functions such as management, collection, and analysis of customer information. The vulnerability stems from the lack of correct validation of client data in WEB applications. An attacker could exploit this vulnerability to execute client code

Trust: 1.71

sources: NVD: CVE-2018-8047 // JVNDB: JVNDB-2018-015583 // VULHUB: VHN-138079

AFFECTED PRODUCTS

vendor:vtigermodel:crmscope:lteversion:7.0.1

Trust: 1.8

sources: JVNDB: JVNDB-2018-015583 // NVD: CVE-2018-8047

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-8047
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-8047
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201906-265
value: MEDIUM

Trust: 0.6

VULHUB: VHN-138079
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-8047
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-138079
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-8047
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-138079 // JVNDB: JVNDB-2018-015583 // CNNVD: CNNVD-201906-265 // NVD: CVE-2018-8047

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-138079 // JVNDB: JVNDB-2018-015583 // NVD: CVE-2018-8047

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201906-265

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201906-265

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015583

PATCH

title:Top Pageurl:https://www.vtiger.com/

Trust: 0.8

sources: JVNDB: JVNDB-2018-015583

EXTERNAL IDS

db:NVDid:CVE-2018-8047

Trust: 2.5

db:JVNDBid:JVNDB-2018-015583

Trust: 0.8

db:CNNVDid:CNNVD-201906-265

Trust: 0.7

db:VULHUBid:VHN-138079

Trust: 0.1

sources: VULHUB: VHN-138079 // JVNDB: JVNDB-2018-015583 // CNNVD: CNNVD-201906-265 // NVD: CVE-2018-8047

REFERENCES

url:https://www.wizlynxgroup.com/security-research-advisories/vuln/wlx-2018-001

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2018-8047

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-8047

Trust: 0.8

url:https://vigilance.fr/vulnerability/vtiger-crm-cross-site-scripting-29485

Trust: 0.6

sources: VULHUB: VHN-138079 // JVNDB: JVNDB-2018-015583 // CNNVD: CNNVD-201906-265 // NVD: CVE-2018-8047

SOURCES

db:VULHUBid:VHN-138079
db:JVNDBid:JVNDB-2018-015583
db:CNNVDid:CNNVD-201906-265
db:NVDid:CVE-2018-8047

LAST UPDATE DATE

2024-11-23T22:51:44.055000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-138079date:2019-06-07T00:00:00
db:JVNDBid:JVNDB-2018-015583date:2019-06-18T00:00:00
db:CNNVDid:CNNVD-201906-265date:2019-06-10T00:00:00
db:NVDid:CVE-2018-8047date:2024-11-21T04:13:11.237

SOURCES RELEASE DATE

db:VULHUBid:VHN-138079date:2019-06-06T00:00:00
db:JVNDBid:JVNDB-2018-015583date:2019-06-18T00:00:00
db:CNNVDid:CNNVD-201906-265date:2019-06-06T00:00:00
db:NVDid:CVE-2018-8047date:2019-06-06T19:29:00.250