4.3
CVSSv2

CVE-2010-0465

Published: 19/03/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the online Documents functionality in SugarCRM 5.2.x prior to 5.2.0l and 5.5.x prior to 5.5.0a allows remote authenticated users to inject arbitrary web script or HTML via the Document Name field.

Vulnerable Product Search on Vulmon Subscribe to Product

sugarcrm sugarcrm 5.2c

sugarcrm sugarcrm 5.2d

sugarcrm sugarcrm 5.2.0g

sugarcrm sugarcrm 5.2a

sugarcrm sugarcrm 5.5

sugarcrm sugarcrm 5.5.0

sugarcrm sugarcrm 5.2g

sugarcrm sugarcrm 5.2h

sugarcrm sugarcrm 5.2e

sugarcrm sugarcrm 5.2f

Exploits

SugarCRM versions prior to 550a and 520l suffer from a cross site scripting vulnerability ...