← back
CVE-2024-48120mediumCWE-79

CVE-2024-48120

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.5epss 0.6%
from disclosure to weapon164 days
Published on NVDOct 14
1st PoC+164d
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating a list.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.