Vulnerability Description
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zurmo | Zurmo Crm | 3.2.1.57987acc3018 |
Related Weaknesses (CWE)
References
- https://bitbucket.org/zurmo/zurmo/issues/432/cross-site-scriptingIssue Tracking
- https://bitbucket.org/zurmo/zurmo/issues/432/cross-site-scriptingIssue Tracking
FAQ
What is CVE-2017-15039?
CVE-2017-15039 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
How severe is CVE-2017-15039?
CVE-2017-15039 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15039?
Check the references section above for vendor advisories and patch information. Affected products include: Zurmo Zurmo Crm.