Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hades484

#21806of 53,630
10.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-10586
4.8
2021-04-14
X2Engine · X2Crm · CVE-2020-21088
Name of the Vulnerable Software and Affected Versions: X2engine X2CRM versions prior to 7.1 Description: The issue allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the `First Name` and `Last Name` fields in the "/index.php/contacts/create" page. This is a Cross Site Scripting (XSS) issue. Recommendations: For versions prior to 7.1, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting input for the `First Name` and `Last Name` fields to minimize the risk of arbitrary script injection.
PT-2021-17384
6.1
2021-04-14
X2Engine · X2Crm · CVE-2021-27288
**Name of the Vulnerable Software and Affected Versions** X2Engine X2CRM version 7.1 **Description** The issue allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the `Comment` field in the "/profile/activity" API endpoint. This can lead to the disclosure of sensitive data. **Recommendations** For version 7.1, update the software to a version that includes a fix for this issue, or as a temporary workaround, consider restricting access to the "/profile/activity" page to minimize the risk of exploitation. Avoid using the `Comment` field in the affected page until the issue is resolved.