Skip to content

Authenticated Reflected Cross-Site Scripting

High
jack7anderson7 published GHSA-ph2c-hvvf-r273 Jun 10, 2024

Package

SuiteCRM

Affected versions

<= 7.14.3
<= 8.6.0

Patched versions

7.14.4
8.6.1

Description

Impact

What kind of vulnerability is it? Who is impacted?
Vulnerability in import module error view allows for XSS attack

Patches

Has the problem been patched? What versions should users upgrade to?

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

References

Are there any links users can visit to find out more?

Cross-Site Scripting (XSS) is a web security vulnerability that allows an attacker to inject malicious scripts into content viewed by other users. This vulnerability exploits the fact that a web application fails to properly sanitize user-generated content before including it in a web page. XSS attacks enable attackers to execute scripts in the victim's browser, which can hijack user sessions, deface websites, or redirect the user to malicious sites.

Severity

High
8.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

CVE ID

CVE-2024-36413

Weaknesses

Credits