Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:19305
HistoryFeb 29, 2008 - 12:00 a.m.

XSS on XRMS- open source CRM

2008-02-2900:00:00
vulners.com
19

XRMS: An open source web enabled LAMP based CRM.
Vulnerability: Confirmation messages upon updates in XRMS are clear text passed across in the URL. Simple test of injection of a script resulted in exposing cross site scripting vulnerability.