CVE-2021-40303: XSS
perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40303?
CVE-2021-40303 is a vulnerability in perfex crm 1.10 that allows for Cross Site Scripting (XSS) attacks via the /clients/profile endpoint.
How severe is CVE-2021-40303?
CVE-2021-40303 has a severity rating of medium with a CVSS score of 5.4.
How does CVE-2021-40303 affect perfex crm 1.10?
CVE-2021-40303 affects perfex crm 1.10 by enabling attackers to carry out Cross Site Scripting (XSS) attacks through the /clients/profile page.
What is Cross Site Scripting (XSS)?
Cross Site Scripting (XSS) is an attack technique where malicious scripts are injected into trusted websites, allowing attackers to steal sensitive information or carry out actions on behalf of the victim.
Is there a fix available for CVE-2021-40303?
At the time of writing, there is no official fix available for CVE-2021-40303. It is recommended to apply security patches or updates from the vendor once they are released.