CVE-2009-3247

Vtiger Crm - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML via the action parameter to phprint.php. NOTE: the query_string vector is already covered by CVE-2008-3101.3.

Exploits (1)

exploitdb WRITEUP VERIFIED
by USH · textwebappsphp
https://www.exploit-db.com/exploits/9450

Scores

EPSS 0.0470
EPSS Percentile 89.2%

Classification

CWE
CWE-79
Status published

Affected Products (2)

vtiger/vtiger_crm
n/a/n/a

Timeline

Published Sep 18, 2009
Tracked Since Feb 18, 2026