Back to Database
Status published
Unknown
CVE-2022-38335
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site...
Vulnerability Description
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-38335
Credits & Attribution
No credits recorded in the NVD database.
References
More from vtiger
View All →CVE-2020-22807
An issue was dicovered in vtiger crm 7.2. Union sql...
Critical
9.8
CVE-2020-19363
Vtiger CRM v7.2.0 allows an attacker to display hidden files,...
Medium
6.5
CVE-2020-19362
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the...
Medium
6.1
CVE-2019-5009
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the...
High
7.2
CVE-2019-19202
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality...
High
8.8
Affected Vendor
vtiger
View all reports →Affected Software
vtiger crm
Vulnerable Versions:
0
Timeline
Official Publish:
September 27th, 2022
Last Modified:
May 21st, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.