SB2018092604 - Cross-site scripting in SalesAgility SuiteCRM
Published: September 26, 2018 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2018-15606)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.
Remediation
Install update from vendor's website.