First published: Tue Jan 16 2018(Updated: )
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | =3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5715 is a vulnerability in SugarCRM 3.5.1 that allows for XSS attacks via a parameter name in the query string (aka a $key variable).
The severity of CVE-2018-5715 is medium, with a severity value of 6.1.
CVE-2018-5715 affects SugarCRM 3.5.1 by allowing for XSS attacks through a parameter name in the query string.
We do not provide information on how to exploit vulnerabilities. It is recommended to update to a patched version of SugarCRM to mitigate the vulnerability.
To fix CVE-2018-5715, update to a version of SugarCRM that includes a patch for the vulnerability.