salesagility/SuiteDocs

salesagility/SuiteDocs

Releases0
Stars65
SuiteCRM - Open source CRM for the world

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.