Security Advisory

CVE-2026-4165

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-15 05:02:07
Last updated 2026-03-17 13:45:03
Assigner VulDB
State PUBLISHED

Description

A vulnerability has been found in Worksuite HR, CRM and Project Management up to 5.5.25. The affected element is an unknown function of the file /account/orders/create. The manipulation of the argument Client Note leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.