PT-2021-12069 · Sugarcrm · Sugarcrm
Benjamin Kunz Mejri
·
Published
2021-10-22
·
Updated
2021-10-26
·
CVE-2020-36501
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SugarCRM version 6.5.18
Description:
The issue allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the
primary address state or alternate address state input fields in the Support module. This enables the execution of malicious code on the victim's browser.Recommendations:
For SugarCRM version 6.5.18, update to a version that includes a fix for this issue, as the current version allows for the execution of arbitrary web scripts or HTML via crafted payloads.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sugarcrm