Description
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/customise_calendar_times.php; login[] parameter to (4) index.php or (5) pub/clients.php; or framed parameter to (6) licence/index.php or (7) licence/view.php.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/36450
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/36454
exploitdb
WRITEUP
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/36451
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/36453
References (8)
Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71827
Exploit x_refsource_misc
https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_browser_crm.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/47217
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/77728
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/77731
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/77729
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/77730
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/77732
Scores
EPSS
0.0677
EPSS Percentile
91.4%
Details
CWE
CWE-79
Status
published
Products (29)
browsercrm/browsercrm
4.604.01
browsercrm/browsercrm
4.605.00
browsercrm/browsercrm
4.607.00
browsercrm/browsercrm
4.610.00
browsercrm/browsercrm
4.611.01
browsercrm/browsercrm
4.612.00
browsercrm/browsercrm
4.614.00
browsercrm/browsercrm
4.615.10
browsercrm/browsercrm
4.615.11
browsercrm/browsercrm
4.616.00
... and 19 more
Published
Oct 25, 2012
Tracked Since
Feb 18, 2026