3.5
CVSSv2

CVE-2017-18004

Published: 31/12/2017 Updated: 11/01/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.

Vulnerable Product Search on Vulmon Subscribe to Product

zurmo zurmo crm 3.2.3

Github Repositories

my CVE list

myCVE Attack Vector CVE ID Reference XSS CVE-2017-17971 wwwcvedetailscom/cve/CVE-2017-17971/ CVE-2017-18004 wwwcvedetailscom/cve/CVE-2017-18004/ Execute Code CVE-2018-3814 wwwcvedetailscom/cve/CVE-2018-3814/

myCVE Attack Vector CVE ID Reference XSS CVE-2017-17971 wwwcvedetailscom/cve/CVE-2017-17971/ CVE-2017-18004 wwwcvedetailscom/cve/CVE-2017-18004/ Execute Code CVE-2018-3814 wwwcvedetailscom/cve/CVE-2018-3814/