Vulnerabilities
Vulnerable Software
Zurmo:  >> Zurmo Crm  >> 3.0.2  Security Vulnerabilities
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.
CVSS Score
5.4
EPSS Score
0.009
Published
2017-04-14
Cross-site scripting (XSS) vulnerability in Zurmo CRM 3.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "What's going on?" profile field.
CVSS Score
3.5
EPSS Score
0.002
Published
2015-07-02


Contact Us

Shodan ® - All rights reserved