CVE

Id
104008  
CVE No.
CVE-2017-7188  
Status
Candidate  
Description
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.  
Phase
Assigned (20170320)  
Votes
None (candidate not yet proposed)  
Comments