PT-2020-16072 · Softradeweb Snc · Wp Smart Crm
Published
2020-09-14
·
Updated
2024-02-14
·
CVE-2020-25375
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP SMART CRM version 1.8.7
Description
The issue affects the Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM, where Cross Site Scripting is possible via several fields, including the
Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and Skype field.Recommendations
For WP SMART CRM version 1.8.7, as a temporary workaround, consider restricting access to these fields until a patch is available. Avoid using these fields in the affected plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Smart Crm