CVE-2026-4165 describes a cross-site scripting (XSS) vulnerability affecting Worksuite HR, CRM and Project Management versions up to 5.5.25. This flaw occurs in the `/account/orders/create` function when processing the "Client Note" argument. The vulnerability has a low CVSS score of 2.4, as it requires high privileges and user interaction for a remote attacker to achieve low integrity impact. While an exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there readily available exploit modules in common frameworks, and community attention remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Worksuite | HR, CRM And Project Management | 5.5.0, 5.5.1, 5.5.10, 5.5.11, 5.5.12, 5.5.13, 5.5.14, 5.5.15, 5.5.16, 5.5.17, 5.5.18, 5.5.19, 5.5.2, 5.5.20, 5.5.21, 5.5.22, 5.5.23, 5.5.24, 5.5.25, 5.5.3, 5.5.4, 5.5.5, 5.5.6, 5.5.7, 5.5.8, 5.5.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.