SB2018092604 - Cross-site scripting in SalesAgility SuiteCRM



SB2018092604 - Cross-site scripting in SalesAgility SuiteCRM

Published: September 26, 2018 Updated: July 17, 2020

Security Bulletin ID SB2018092604
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Cross-site scripting (CVE-ID: CVE-2018-15606)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.


Remediation

Install update from vendor's website.