PT-2020-16072 · Softradeweb Snc · Wp Smart Crm

Published

2020-09-14

·

Updated

2024-02-14

·

CVE-2020-25375

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP SMART CRM version 1.8.7
Description The issue affects the Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM, where Cross Site Scripting is possible via several fields, including the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and Skype field.
Recommendations For WP SMART CRM version 1.8.7, as a temporary workaround, consider restricting access to these fields until a patch is available. Avoid using these fields in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-25375

Affected Products

Wp Smart Crm