First published: Tue Dec 28 2021(Updated: )
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SalesAgility SuiteCRM | <7.10.35 | |
SalesAgility SuiteCRM | >=7.11.0<7.12.2 | |
<7.10.35 | ||
>=7.11.0<7.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-45903.
The severity of CVE-2021-45903 is medium with a CVSS score of 6.1.
SuiteCRM versions before 7.10.35, and 7.11.x and 7.12.x before 7.12.2 are affected by CVE-2021-45903.
CVE-2021-45903 is a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to introduce arbitrary JavaScript via attachments upload in the web interface of SuiteCRM.
Yes, you can find more information about CVE-2021-45903 at the following references: [Reference 1](https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_35), [Reference 2](https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_2), [Reference 3](https://github.com/ach-ing/cves/blob/main/CVE-2021-45903.md).