CVE-2018-20816

An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*
cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*

History

22 Jul 2021, 15:50

Type Values Removed Values Added
CPE cpe:2.3:a:salesagility:suitcrm:*:*:*:*:*:*:*:* cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*

Information

Published : 2019-04-05 16:29

Updated : 2024-02-04 20:20


NVD link : CVE-2018-20816

Mitre link : CVE-2018-20816

CVE.ORG link : CVE-2018-20816


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')