First published: Fri Oct 22 2021(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | =6.5.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28956 is a vulnerability that allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary or alternate address state input fields in the Sales module of SugarCRM v6.5.18.
CVE-2020-28956 has a severity rating of medium, with a score of 5.4 (based on the CVSS v3.1 scoring system).
Attackers can exploit CVE-2020-28956 by submitting crafted payloads in the primary or alternate address state input fields, which can execute arbitrary web scripts or HTML.
Yes, applying the latest update or patch provided by SugarCRM can fix the CVE-2020-28956 vulnerability.
You can find more information about CVE-2020-28956 at the following reference link: [https://www.vulnerability-lab.com/get_content.php?id=2249]