CVE-2008-3101

vtiger CRM 5.0.4 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Fabian Fingerle · textwebappsphp
https://www.exploit-db.com/exploits/32307

Scores

EPSS 0.0732
EPSS Percentile 91.6%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

vtiger/vtiger_crm

Timeline

Published Sep 03, 2008
Tracked Since Feb 18, 2026