First published: Fri Jun 02 2023(Updated: )
A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Customer Relationship Management | <=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-3058.
The severity level of CVE-2023-3058 is medium with a CVSS score of 5.4.
The User Profile Handler component of 07FLY CRM up to version 1.2.0 is affected by CVE-2023-3058.
CVE-2023-3058 allows for remote attackers to initiate cross-site scripting attacks, potentially leading to the manipulation of user profiles.
Yes, there are references available for CVE-2023-3058. You can find them at the following links: [Link 1](https://gitee.com/07fly/FLY-CRM/issues/I76K4N), [Link 2](https://vuldb.com/?ctiid.230560), [Link 3](https://vuldb.com/?id.230560).