Novaksolutions maintains a PHP SDK for the Infusionsoft customer relationship management platform, presenting a narrow but potentially broad downstream attack surface through integration into merchant and service-provider applications. The observed vulnerability exposure centers on cross-site scripting weaknesses in web-page generation, a common input-handling risk in application SDKs distributed to third parties. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Novaksolutions over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6216MEDIUM novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution | Jul 3, 2019 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Novaksolutions.
Media articles that mention a CVE ID that affects a product developed by Novaksolutions — matched by CVE ID, not by vendor name.