Reflected Cross-Site Scripting (XSS) Vulnerability in X2CRM Open Source Sales CRM 6.6 and 6.9

Reflected Cross-Site Scripting (XSS) Vulnerability in X2CRM Open Source Sales CRM 6.6 and 6.9

CVE-2022-48177 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScript that will be executed by the victim user's browser.

Learn more about our Crm Penetration Testing.