Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://elitecrm.co/ | product |
https://hazemhussien99.wordpress.com/2024/01/07/cve-2022-40361-disclosure/ | third party advisory |