Zurmo
9 known vulnerabilities
Top Products
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.
Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/defau
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.
An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in
Frequently Asked Questions
How many CVEs affect Zurmo?
Zurmo has 9 CVE records in our database, including 0 critical and 0 high severity vulnerabilities.
What are the most severe Zurmo vulnerabilities?
Zurmo has 0 critical severity (CVSS 9.0+) and 0 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Zurmo vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Zurmo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Zurmo Vulnerabilities
CyberStrike scans your infrastructure for Zurmo vulnerabilities and provides real-time remediation guidance.
Get Started