First published: Wed Oct 10 2018(Updated: )
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | >=6.5.0<=6.5.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-17784 is medium (6.1).
CVE-2018-17784 refers to multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
An attacker can exploit CVE-2018-17784 by leveraging the vulnerabilities in YUI and FlashCanvas to execute a cross-site scripting (XSS) attack.
To fix CVE-2018-17784, it is recommended to upgrade SugarCRM Community Edition to a version that is not affected by the vulnerabilities.
Yes, the following references provide more information on CVE-2018-17784: [Twitter](https://twitter.com/purplemet/status/1043979681186369537), [Exploit-DB](https://www.exploit-db.com/exploits/45594/), [Purplemet Blog](https://www.purplemet.com/blog/sugarcrm-multiple-xss-vulnerabilities).