What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4.
Explanation of Vulnerability in Simple Terms
CRM Perks Forms versions up to 1.1.4 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts into form data. When other users view the affected form or its data, the injected script executes in their browser, potentially allowing the attacker to steal session tokens, modify page content, or perform actions on their behalf.
What an attacker can do
Inject malicious scripts that execute when other users view form data, stealing sessions or modifying page content.
Potential impact on your site
Users' accounts and data are at risk if attackers inject scripts into forms. Visitor sessions can be compromised.
Conditions required to exploit
Attacker needs a low-privilege account and must trick a user into viewing a form containing the injected payload.
Key dates
External resources
Related vulnerabilities