CVE-2011-5214
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
25/10/2012
Last modified:
11/04/2025
Description
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:browsercrm:browsercrm:*:*:*:*:*:*:*:* | 5.100.01 (including) | |
| cpe:2.3:a:browsercrm:browsercrm:4.604.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.605.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.607.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.610.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.611.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.612.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.614.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.615.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.615.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.616.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.617.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.619.00:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.620.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:browsercrm:browsercrm:4.622.00:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/77728
- http://osvdb.org/77729
- http://osvdb.org/77730
- http://osvdb.org/77731
- http://osvdb.org/77732
- http://secunia.com/advisories/47217
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71827
- https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_browser_crm.html
- http://osvdb.org/77728
- http://osvdb.org/77729
- http://osvdb.org/77730
- http://osvdb.org/77731
- http://osvdb.org/77732
- http://secunia.com/advisories/47217
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71827
- https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_browser_crm.html



