First published: Wed Aug 18 2021(Updated: )
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are not blocked.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SalesAgility SuiteCRM | <7.11.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39267 is a vulnerability that allows persistent cross-site scripting (XSS) in the web interface of SuiteCRM before version 7.11.19.
CVE-2021-39267 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files.
CVE-2021-39267 has a severity level of medium (6.1).
To fix CVE-2021-39267, upgrade SuiteCRM to version 7.11.19 or later.
You can find more information about CVE-2021-39267 on the SuiteCRM documentation website, the SuiteCRM GitHub repository, and a blog post on the vulnerability.