First published: Tue Sep 27 2022(Updated: )
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vtiger Vtiger Crm | <=7.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38335 is a stored cross-site scripting (XSS) vulnerability found in Vtiger CRM v7.4.0.
CVE-2022-38335 affects Vtiger CRM v7.4.0 through a stored XSS vulnerability in the e-mail template modules.
CVE-2022-38335 has a severity rating of medium (5.4).
The CWE ID for CVE-2022-38335 is 79, which corresponds to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Yes, you can find more information about CVE-2022-38335 at the following references: [1] https://code.vtiger.com/vtiger/vtigercrm [2] https://github.com/sbaresearch/advisories/tree/public/2022/SBA-ADV-20220328-01_Vtiger_CRM_Stored_Cross-Site_Scripting [3] https://www.vtiger.com/