VYPR
Unrated severityNVD Advisory· Published May 21, 2025· Updated May 21, 2025

CVE-2025-45755

CVE-2025-45755

Description

A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improperly sanitizes user input, leading to persistent script execution.

Affected products

2
  • Vtiger/CRM Open Source Editiondescription
  • Vtiger/Vtigercrmllm-fuzzy
    Range: = 8.3.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.