Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://andrea0.medium.com | third party advisory |
https://andrea0.medium.com/analysis-of-cve-2024-54687-9d82f4c0eaa8 | third party advisory exploit |