vendor:
SugarCRM
by:
Guilherme Assmann
6.1
CVSS
MEDIUM
Cross-site Scripting (XSS)
79
CWE
Product Name: SugarCRM
Affected Version From: 3.5.1
Affected Version To: 3.5.1
Patch Exists: YES
Related CWE: CVE-2018-5715
CPE: a:sugarcrm:sugarcrm:3.5.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cesa-2018-0512/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0512/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0496/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4021/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4019/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4018/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4012/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0094/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0093/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-elsa-2018-4011/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-rhsa-2018-0053/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0002-cve-2017-5715/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0004-cve-2017-5715-fusion/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0002-cve-2017-5715-fusion/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0004-cve-2017-5715-workstation/, https://www.rapid7.com/db/vulnerabilities/vmsa-2018-0002-cve-2017-5715-workstation/
Other Scripts:
N/A
Platforms Tested: Kali Linux, Windows 7, 8.1, 10, Ubuntu - Firefox
2017
sugarCRM 3.5.1 XSS refeclted
The vulnerability is in the key parameter of phpprint.php. The $key variable is not encoded, which allows for easy XSS exploitation. The proof of concept is http://vulnerable/index.php?action=Login&module=Users&print=a&"/><script>alert('xss')</script>
Mitigation:
Encode the $key variable in phpprint.php.