CVE-2024-48120
MEDIUMX2CRM 8.5 - Authenticated Stored Cross-Site Scripting in Opportunities Module Name Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48120. PoCs published by Okan Kurtulus.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in X2CRM v8.5 by injecting a malicious payload into the 'Name' field of the 'Create List' feature under the 'Opportunities' section. The payload is triggered when navigating back to the 'Lists' tab.
Description
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating a list.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in X2CRM v8.5 by injecting a malicious payload into the 'Name' field of the 'Create List' feature under the 'Opportunities' section. The payload is triggered when navigating back to the 'Lists' tab.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N