vendor:
SugarCRM Community Edition
by:
Purplemet Security
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: SugarCRM Community Edition
Affected Version From: 6.5.26
Affected Version To: 6.5.26
Patch Exists: NO
Related CWE: CVE-2018-17784
CPE: a:sugarcrm:sugarcrm_community_edition:6.5.26
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 16.04
2018
SugarCRM 6.5.26 – Cross-Site Scripting
A vulnerability in uploader.swf, io.swf and flashcanvas.swf in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. SugarCRM Community Edition 6.5 had reached its end-of-life and is no longer supported. 6.5.26 is the last version and no patches will be provided by the vendor.
Mitigation:
No patches will be provided by the vendor.