X2Engine / X2CRM

X2CRM Open Source CRM - PHP
http://www.x2crm.com
343 stars 167 forks source link

Multiple Cross Site Scripting in X2CRM 7.1 #183

Open Hades484 opened 3 years ago

Hades484 commented 3 years ago

Hi,

I have found the multiple stored XSS in the X2crm version 7.1. I like to report them and get the CVE.

Location: http://localhost/x2crm/x2engine/index.php/contacts/create Parameter: Last Name Payload inserted 1 Execution of the payload 2

Location: http://localhost/x2crm/x2engine/index.php//profile/activity Parameter: comments payload inserted 1 Execution of the payload 2