Vtiger CRM v.6.1 and before is vulnerable to Cross Site...
Moderate severity
Unreviewed
Published
Jan 10, 2025
to the GitHub Advisory Database
•
Updated Jan 13, 2025
Description
Published by the National Vulnerability Database
Jan 10, 2025
Published to the GitHub Advisory Database
Jan 10, 2025
Last updated
Jan 13, 2025
Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.
References