Medium severity5.4NVD Advisory· Published Apr 14, 2017· Updated May 13, 2026
CVE-2017-7188
CVE-2017-7188
Description
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/97681nvdThird Party AdvisoryVDB Entry
- bitbucket.org/zurmo/zurmo/issues/426/to-report-a-xss-security-vulnerability-innvdThird Party Advisory
News mentions
0No linked articles in our index yet.