CVE-2017-7188: Zurmo CRM
Medium severity, CVSS 5.4. EPSS: 1.4% chance of exploitation in the next 30 days.
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.
Affected products
- Zurmo Zurmo CRM: up to and including 3.1.1
Published 2017-04-14. Last modified 2026-06-17.