CVE-2010-2718

CruxSoftware CruxPA 2.00 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in CruxSoftware CruxPA 2.00, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) txtusername parameter to login.php, (2) todo parameter to newtodo.php, and unspecified vectors to (3) newtelephone.php and (4) newappointment.php.

Scores

EPSS 0.0054
EPSS Percentile 67.5%

Classification

CWE
CWE-79
Status published

Affected Products (2)

cruxsoftware/cruxpa
n/a/n/a

Timeline

Published Jul 13, 2010
Tracked Since Feb 18, 2026