← Volver a CVEs
CVE-2022-48177
MEDIUM5.4
Descripcion
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScript that will be executed by the victim user's browser.
Detalles CVE
Puntuacion CVSS v3.15.4
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioREQUIRED
Publicado4/15/2023
Ultima modificacion1/30/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
x2engine:x2crm
Debilidades (CWE)
CWE-79CWE-79
Referencias
https://sourceforge.net/projects/x2engine/(cve@mitre.org)
http://packetstormsecurity.com/files/171792/X2CRM-6.6-6.9-Cross-Site-Scripting.html(af854a3a-2127-422b-91ae-364da2661108)
https://sourceforge.net/projects/x2engine/(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.