CVE-2013-7326 Information

Description

Cross-site scripting (XSS) vulnerability in vTiger CRM 5.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) return_url parameter to modules\com_vtiger_workflow\savetemplate.php or unspecified vectors to (2) deletetask.php (3) edittask.php (4) savetask.php or (5) saveworkflow.php.

Reference

http://archives.neohapsis.com/archives/bugtraq/2013-12/0052.html http://osvdb.org/100897 http://packetstormsecurity.com/files/124402 http://www.enkomio.com/Advisory/SOJOBO-ADV-13-05 http://www.securityfocus.com/bid/64236 https://exchange.xforce.ibmcloud.com/vulnerabilities/89662 Cross-site scripting (XSS) vulnerability in vTiger CRM 5.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) return_url parameter to modules\com_vtiger_workflow\savetemplate.php or unspecified vectors to (2) deletetask.php (3) edittask.php (4) savetask.php or (5) saveworkflow.php.

Share on: