vendor:
Realtime CRM Automation
by:
Haythem Arfaoui (CBTW Team)
6.1
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Realtime CRM Automation
Affected Version From: 6.18.17
Affected Version To: 6.18.17 and below
Patch Exists: NO
Related CWE: CVE-2024-42831
CPE: a:elaine:realtime_crm_automation:6.18.17
Platforms Tested: Windows, Linux
2024
Elaine’s Realtime CRM Automation 6.18.17 – Reflected XSS
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation version 6.18.17 and below allows malicious users to run arbitrary JavaScript code in a victim's web browser by inserting a specially crafted payload into the dialog parameter at wrapper_dialog.php.
Mitigation:
To mitigate this vulnerability, sanitize and validate user inputs before processing them to prevent the execution of malicious scripts.