← Back

CVE-2010-3911

nvd nist
Published: Nov 26, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username (aka default_user_name) field or (2) the password field in a Users Login action to index.php, or (3) the label parameter in a Settings GetFieldInfo action to index.php, related to modules/Settings/GetFieldInfo.php.

Affected (24)

Products: Vtiger: Vtiger Crm
1 product
Vtiger Crm
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Vtiger
Up to 5.2.0
Version 1.0
Version 2.0.1
Version 2.0
Version 2.1
Version 3.0
Version 3.0 beta
Version 3.2
Version 3
Version 4.0.1
Version 4.0
Version 4.2.4
Version 4.2
Version 4.2
Version 4
Version 4 beta
Version 4 rc1
Version 5.0.0
Version 5.0.2
Version 5.0.3
Version 5.0.4
Version 5.0.4 rc
Version 5.1.0
Version 5.1.0 rc

References (10)

Timeline

No history available yet.