CVE-2023-3058: 07FLY CRM User Profile cross site scripting
A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230560.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-3058.
What is the severity level of CVE-2023-3058?
The severity level of CVE-2023-3058 is medium with a CVSS score of 5.4.
Which component is affected by CVE-2023-3058?
The User Profile Handler component of 07FLY CRM up to version 1.2.0 is affected by CVE-2023-3058.
What is the impact of CVE-2023-3058?
CVE-2023-3058 allows for remote attackers to initiate cross-site scripting attacks, potentially leading to the manipulation of user profiles.
Are there any references for CVE-2023-3058?
Yes, there are references available for CVE-2023-3058. You can find them at the following links: [Link 1](https://gitee.com/07fly/FLY-CRM/issues/I76K4N), [Link 2](https://vuldb.com/?ctiid.230560), [Link 3](https://vuldb.com/?id.230560).