CVE-2020-21088
Summary
| CVE | CVE-2020-21088 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-14 14:15:00 UTC |
| Updated | 2021-04-21 01:49:00 UTC |
| Description | Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fields in "/index.php/contacts/create page" |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Cross Site Scripting in X2CRM 7.1 · Issue #183 · X2Engine/X2CRM · GitHub | MISC | github.com | |
| Stored XSS in Contact firsname and last name · Issue #161 · X2Engine/X2CRM · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.