PT-2026-45685 · Cordyscrm · Cordyscrm
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CordysCRM versions prior to 1.7.0
Description
Cross site scripting can be initiated remotely via the manipulation of the
Description argument within the Save() function of the src/main/java/cn/cordys/crm/system/service/ModuleFormService.java file, which is part of the ModuleFormController component.Recommendations
Update to version 1.7.0.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cordyscrm