vendor:
1CRM On-Premise Software
by:
Kusol Watchara-Apanukorn
5.4
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: 1CRM On-Premise Software
Affected Version From: 8.5.7
Affected Version To: 8.5.7
Patch Exists: YES
Related CWE: CVE-2019-14221
CPE: a:1crm:1crm_on-premise_software
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7.6.1810 (Core)
2019
1CRM On-Premise Software 8.5.7 – Cross-Site Scripting
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
Mitigation:
Validate and escape user input before displaying it on the page.