CVE-2018-19506: Zurmo

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.

Affected products

  • Zurmo Zurmo: version 3.2.4 only

Published 2018-12-19. Last modified 2026-06-17.