CVE-2011-4670

N/A Unknown
Published: December 02, 2011 Modified: April 29, 2026
View on NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) viewname parameter in a CalendarAjax action, (2) activity_mode parameter in a DetailView action, (3) contact_id and (4) parent_id parameters in an EditView action, (5) day, (6) month, (7) subtab, (8) view, and (9) viewOption parameters in the index action, and (10) start parameter in the ListView action to the Calendar module; (11) return_action and (12) return_module parameters in the EditView action, and (13) query parameter in an index action to the Campaigns module; (14) return_url and (15) workflow_id parameters in an editworkflow action to the com_vtiger_workflow module; (16) display_view parameter in an index action to the Dashboard module; (17) closingdate_end, (18) closingdate_start, (19) date_closed, (20) owner, (21) leadsource, (22) sales_stage, and (23) type parameters in a ListView action to the Potentials module; (24) folderid parameter in a SaveandRun action to the Reports module; (25) returnaction and (26) groupId parameters in a createnewgroup action, (27) mode and (28) parent parameters in a createrole action, (29) src_module in a ModuleManager action, (30) mode and (31) profile_id parameters in a profilePrivileges action, and (32) roleid parameter in a RoleDetailView to the Settings module; and (33) action parameter to the Home module and (34) module parameter to phprint.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/76005
Source: cve@mitre.org
Broken Link
http://osvdb.org/76006
Source: cve@mitre.org
Broken Link
http://seclists.org/fulldisclosure/2011/Oct/154
Source: cve@mitre.org
Exploit Mailing List Third Party Advisory
http://www.securityfocus.com/bid/49927
Source: cve@mitre.org
Exploit Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/70306
Source: cve@mitre.org
Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/36203/
Source: cve@mitre.org
Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/36204/
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://osvdb.org/76005
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://osvdb.org/76006
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://seclists.org/fulldisclosure/2011/Oct/154
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Mailing List Third Party Advisory
http://www.securityfocus.com/archive/1/519993/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/49927
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Third Party Advisory VDB Entry
http://yehg.net/lab/pr0js/advisories/%5BvTiger_5.2.1%5D_XSS
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/70306
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/36203/
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/36204/
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
3.0%
85th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

vtiger