Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap CVE-2008-1129.
- http://securityreason.com/securityalert/4081
- https://www.exploit-db.com/exploits/6131
No PoCs found on GitHub currently.