Loading
Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.
Use CWE-79, Vtiger vendor hub and Vtiger Crm product page to widen CVE-2024-54687 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-44779, CVE-2024-44778 and CVE-2024-44777 for nearby disclosures in the same product family.