Vulnerability Details CVE-2022-48178
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 79.9%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2022-48178
-
cpe:2.3:a:x2crm:x2crm:6.6
-
cpe:2.3:a:x2crm:x2crm:6.9