vendor:
MyIT CRM
by:
Juan Manuel García
3,5
CVSS
MEDIUM
Reflected Cross-Site Scripting (XSS)
79
CWE
Product Name: MyIT CRM
Affected Version From: MyIT CRM ver.0.2.8.1
Affected Version To: MyIT CRM ver.0.2.8.1
Patch Exists: YES
Related CWE: N/A
CPE: MyIT CRM
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Any running MyIT CRM ver.0.2.8.1
2010
Multiple Cross-Site Scripting (XSS) in MyIT CRM
Multiple Reflected Cross Site Scripting vulnerabilities were found in MyIT CRM ver.0.2.8.1 web console, because the application fails to sanitize user-supplied input. The vulnerabilities can be triggered by any logged-in user who is able to access the “View Employees” functionality. Parameters name, employee_id, and page are not properly sanitized. Other parameters might also be affected.
Mitigation:
Sanitize user-supplied input.