PT-2024-11628 · Elite Crm · Elite Crm

Hazem Hussien

·

Published

2024-01-11

·

Updated

2025-06-17

·

CVE-2022-40361

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Elite CRM version 1.2.11
Description A Cross Site Scripting issue allows an attacker to execute arbitrary code via the language parameter to the "/ngs/login" endpoint.
Recommendations For Elite CRM version 1.2.11, avoid using the language parameter in the "/ngs/login" endpoint until a fix is available. Consider restricting access to this endpoint as a temporary mitigation measure.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-40361

Affected Products

Elite Crm