Bug: XSS on XRMS- open source CRM (WLB-2008030002 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: XSS on XRMS- open source CRM
 Credit: vijayv
 Date: 2008.03.04
 CWE: CWE-79 (Show similar)
 CVE: CVE-2008-1129 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

XRMS: An open source web enabled LAMP based CRM.

Vulnerability: Confirmation messages upon updates in XRMS are clear text passed across in the URL. Simple test of
injection of a script resulted in exposing cross site scripting vulnerability.

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com