CVE-2011-4680

Multiple cross-site scripting (XSS) vulnerabilities in the customer portal in vtiger CRM before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
vtigervtiger_crm
𝑥
≤ 5.1.0
vtigervtiger_crm
1.0
vtigervtiger_crm
2.0
vtigervtiger_crm
2.0.1
vtigervtiger_crm
2.1
vtigervtiger_crm
3.0
vtigervtiger_crm
3.0:beta
vtigervtiger_crm
3.2
vtigervtiger_crm
4.0
vtigervtiger_crm
4.0.1
vtigervtiger_crm
4.2
vtigervtiger_crm
4.2
vtigervtiger_crm
4.2:patch1
vtigervtiger_crm
4.2.4
vtigervtiger_crm
5.0.0
vtigervtiger_crm
5.0.2
vtigervtiger_crm
5.0.3
vtigervtiger_crm
5.0.4
vtigervtiger_crm
5.0.4:rc
vtigervtiger_crm
5.1.0:rc
vtigervtiger_crm
5.2.1
𝑥
= Vulnerable software versions