CVE-2014-5521: Xrms CRM Project Xrms CRM
Medium severity, CVSS 6.5. EPSS: 7.1% chance of exploitation in the next 30 days.
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.
Affected products
- Xrms CRM Project Xrms CRM: version 1.99.2 only
Published 2014-09-02. Last modified 2026-06-17.