CVE-2014-5521: Xrms CRM Project Xrms CRM

Medium severity, CVSS 6.5. EPSS: 7.1% chance of exploitation in the next 30 days.

plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.

Affected products

Published 2014-09-02. Last modified 2026-06-17.