Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context.
History

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context.
Title Zstore 6.5.4 - Reflected Cross-Site Scripting (XSS)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-13T22:56:33.201Z

Reserved: 2025-12-20T16:31:20.900Z

Link: CVE-2023-53985

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-13T23:15:59.607

Modified: 2026-01-13T23:15:59.607

Link: CVE-2023-53985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.