CVE-2024-4754: NEXT4BIZ CRM & Bpm Software Business Process Manangement Bpm
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS. This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
Affected products
- NEXT4BIZ CRM & Bpm Software Business Process Manangement Bpm: from 6.6.4.4, before 6.6.4.5 (fixed in 6.6.4.5)
Published 2024-06-24. Last modified 2026-06-17.