CVE-2020-28961: XSS
Published Oct 22, 2021
·Updated
Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter.
Affected Software
1 affected component
Perfexcrm Perfex Crm=2.4.4
Event History
Oct 22, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-28961?
The severity of CVE-2020-28961 is medium.
2
How does CVE-2020-28961 affect Perfex CRM v2.4.4?
CVE-2020-28961 affects Perfex CRM v2.4.4 through a stored cross-site scripting (XSS) vulnerability in the ./clients/client component via the company name parameter.
3
What is the vulnerability ID of Perfex CRM v2.4.4?
The vulnerability ID of Perfex CRM v2.4.4 is CVE-2020-28961.
4
What is the CWE ID of CVE-2020-28961?
The CWE ID of CVE-2020-28961 is 79.
5
How can I fix the stored cross-site scripting (XSS) vulnerability in Perfex CRM v2.4.4?
To fix the stored cross-site scripting (XSS) vulnerability in Perfex CRM v2.4.4, apply the necessary patches or updates provided by Perfex CRM.