CVE-2024-8867: Perfex CRM Parameter Clients.php cross site scripting
A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8867?
CVE-2024-8867 is classified as a problematic vulnerability with potential for cross site scripting.
How do I fix CVE-2024-8867?
To fix CVE-2024-8867, update Perfex CRM to a newer version that addresses this vulnerability.
What is affected by CVE-2024-8867?
CVE-2024-8867 affects Perfex CRM version 3.1.6, specifically the application/controllers/Clients.php file.
What type of vulnerability is CVE-2024-8867?
CVE-2024-8867 is a cross site scripting vulnerability that can be exploited through manipulation of the 'message' argument.
Who is affected by CVE-2024-8867?
Any users running Perfex CRM version 3.1.6 may be affected by the vulnerabilities presented in CVE-2024-8867.