PT-2022-15245 · Unknown · Daybyday Crm

Published

2022-01-05

·

Updated

2022-01-08

·

CVE-2022-22109

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Daybyday CRM version 2.2.0
Description The issue allows low privileged application users to store malicious scripts in the title field of new tasks. These scripts are executed in a victim's browser when they open the "/tasks" page to view all the tasks. This is a Stored Cross-Site Scripting (XSS) issue.
Recommendations For Daybyday CRM version 2.2.0, consider disabling the ability to input scripts in the title field of new tasks until a patch is available. Restrict access to the "/tasks" page to minimize the risk of exploitation. Avoid using the title field in the affected task creation functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22109
GHSA-JR37-66PJ-36V7

Affected Products

Daybyday Crm