CVE-2022-48178
MEDIUMX2CRM 6.6-6.9 - Stored Cross-Site Scripting via Create Action Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-48178. PoCs published by Betul Denizler.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in X2CRM v6.6/6.9 via the 'Actions[subject]' parameter in an authenticated POST request. The payload is injected into the action subject field and executed when viewed.
Description
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in X2CRM v6.6/6.9 via the 'Actions[subject]' parameter in an authenticated POST request. The payload is injected into the action subject field and executed when viewed.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N