EmreOvunc/Vtiger-CRM-Vulnerabilities

EmreOvunc/Vtiger-CRM-Vulnerabilities

Releases1
Frequency
Last Release
Stars6
Vtiger CRM v7.2.0 has Cross-Site Scripting (XSS) and directory listing vulnerabilities.

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.

6.5 MEDIUM4.3 MEDIUM

Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.