First published: Fri Oct 22 2021(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | =6.5.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-36501.
The severity rating of CVE-2020-36501 is medium, with a CVSS score of 5.4.
The version affected by CVE-2020-36501 is SugarCRM v6.5.18.
Attackers can exploit CVE-2020-36501 by entering crafted payloads into the primary address state or alternate address state input fields in the Support module of SugarCRM.
Yes, it is recommended to upgrade to a patched version of SugarCRM to mitigate CVE-2020-36501.