CVE-2010-3911
26.11.2010, 20:00
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username (aka default_user_name) field or (2) the password field in a Users Login action to index.php, or (3) the label parameter in a Settings GetFieldInfo action to index.php, related to modules/Settings/GetFieldInfo.php.
Vendor | Product | Version |
---|---|---|
vtiger | vtiger_crm | 𝑥 ≤ 5.2.0 |
vtiger | vtiger_crm | 1.0 |
vtiger | vtiger_crm | 2.0 |
vtiger | vtiger_crm | 2.0.1 |
vtiger | vtiger_crm | 2.1 |
vtiger | vtiger_crm | 3.0 |
vtiger | vtiger_crm | 3.0:beta |
vtiger | vtiger_crm | 3.2 |
vtiger | vtiger_crm | 4.0 |
vtiger | vtiger_crm | 4.0.1 |
vtiger | vtiger_crm | 4.2 |
vtiger | vtiger_crm | 4.2 |
vtiger | vtiger_crm | 4.2.4 |
vtiger | vtiger_crm | 5.0.0 |
vtiger | vtiger_crm | 5.0.2 |
vtiger | vtiger_crm | 5.0.3 |
vtiger | vtiger_crm | 5.0.4 |
vtiger | vtiger_crm | 5.0.4:rc |
vtiger | vtiger_crm | 5.1.0 |
vtiger | vtiger_crm | 5.1.0:rc |
𝑥
= Vulnerable software versions
References