CVE-2015-5075: x2engine x2crm
Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an administrative account via a crafted request to index.php/users/create.
Affected products
- x2engine x2crm: up to and including 5.0.9
Published 2015-09-29. Last modified 2026-06-17.