First published: Wed Nov 18 2020(Updated: )
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SalesAgility SuiteCRM | <=7.11.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14208 is a vulnerability in SuiteCRM 7.11.13 that allows remote authenticated attackers to inject arbitrary web script or HTML through stored cross-site scripting (XSS) in the Documents preview functionality.
CVE-2020-14208 has a severity rating of 5.4 (medium).
CVE-2020-14208 affects SuiteCRM 7.11.13 and allows remote authenticated attackers to inject arbitrary web script or HTML.
To fix CVE-2020-14208, it is recommended to update SuiteCRM to a version that is not affected by the vulnerability.
More information about CVE-2020-14208 can be found at the following link: [https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2020-008](https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2020-008)