X2CRM Open Source Sales CRM 6.6 and 6.9 exists to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
x2crm x2crm 6.9 |
||
x2crm x2crm 6.6 |