CVE-2024-48120

MEDIUM

X2CRM 8.5 - Authenticated Stored Cross-Site Scripting in Opportunities Module Name Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-48120. PoCs published by Okan Kurtulus.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in X2CRM v8.5 by injecting a malicious payload into the 'Name' field of the 'Create List' feature under the 'Opportunities' section. The payload is triggered when navigating back to the 'Lists' tab.

Description

X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating a list.

Exploits (1)

exploitdb WORKING POC
by Okan Kurtulus · webappsphp
https://www.exploit-db.com/exploits/52098

This exploit demonstrates a stored XSS vulnerability in X2CRM v8.5 by injecting a malicious payload into the 'Name' field of the 'Create List' feature under the 'Opportunities' section. The payload is triggered when navigating back to the 'Lists' tab.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: X2CRM v8.5
Auth required
Prerequisites: Valid user credentials · Access to the 'Opportunities' section
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0062
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
x2engine/x2crm 8.5
Published Oct 14, 2024
Tracked Since Feb 18, 2026