header-logo
Suggest Exploit
vendor:
VTiger v7.0 CRM
by:
Vulnerability Laboratory
9.8
CVSS
CRITICAL
Persistent Cross Site Scripting (XSS)
79
CWE
Product Name: VTiger v7.0 CRM
Affected Version From: v7.0
Affected Version To: v7.0
Patch Exists: YES
Related CWE: CVE-2020-14092
CPE: a:vtiger:vtiger_crm:7.0
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows, Linux, Mac
2020

VTiger v7.0 CRM – (To) Persistent Email Vulnerability

A persistent input validation web vulnerability has been discovered in the official VTiger v7.0 CRM web-application. The vulnerability allows remote attackers to inject malicious script codes to the application-side of the vulnerable module. The persistent vulnerability is located in the `To` parameter of the `Email` module. Remote attackers are able to inject own malicious script codes to the vulnerable `To` parameter. The attack vector of the vulnerability is persistent and the request method to inject is POST. The security risk of the persistent web vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 4.8. Exploitation of the persistent input validation web vulnerability requires no privileged web-application user account and low user interaction. Successful exploitation of the vulnerability results in session hijacking, persistent phishing attacks, persistent external redirects to malicious sources and persistent manipulation of affected or connected module context.

Mitigation:

Update to the latest version of VTiger v7.0 CRM
Source

Exploit-DB raw data: