CVE-2018-8047

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/06/2019
Last modified:
07/06/2019

Description

vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vtiger:vtiger_crm:*:*:*:*:*:*:*:* 7.0.1 (including)