First published: Fri Mar 19 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the online Documents functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a allows remote authenticated users to inject arbitrary web script or HTML via the Document Name field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SugarCRM | =5.2.0g | |
SugarCRM | =5.2a | |
SugarCRM | =5.2c | |
SugarCRM | =5.2d | |
SugarCRM | =5.2e | |
SugarCRM | =5.2f | |
SugarCRM | =5.2g | |
SugarCRM | =5.2h | |
SugarCRM | =5.5-beta1 | |
SugarCRM | =5.5-beta2 | |
SugarCRM | =5.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-0465 is considered moderate due to its impact on authenticated users being able to execute arbitrary scripts.
To fix CVE-2010-0465, upgrade to SugarCRM version 5.2.0l or 5.5.0a or later.
CVE-2010-0465 affects SugarCRM versions 5.2.x before 5.2.0l and 5.5.x before 5.5.0a.
CVE-2010-0465 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2010-0465 can affect remote authenticated users, regardless of their role.