Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS)
Vulnerability Description
Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53985
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- nu11secur1ty
Affected Vendor
Zippy
View all reports →