Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap CVE-2008-1129.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
XRMS CRM msg参数跨站脚本漏洞
Vulnerability Description
XRMS CRM 是一个用PHP 开发的开源客户关系管理系统和销售团队自动化管理工具。 XRMS CRM 1.99.2版本存在多个跨站脚本攻击漏洞。远程攻击者可以借助到未明组件的msg参数,注入任意的web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A