Back

MEDIUM

Stored Cross-Site Scripting (XSS) in Energy CRM by Status Tracker

Published Oct 23, 2025

Description

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of user input by sending a POST request to “/crm/create_job_submit.php”, using the “JobCreatedBy” parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

Affected products

Remediation

Vendor solution

No solution has been reported at this time.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Oct 23, 2025
Updated Oct 23, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Oct 23, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a