
CVE-2017-14510
https://notcve.org/view.php?id=CVE-2017-14510
17 Sep 2017 — An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This attack vector is mitigated by proper validating the redirect URL values being passed along. Existe un problema en SugarCRM en versiones anteriores a la 7.7.2.3, en versiones 7.8.x anteriores a la 7.8.2.2 y en versiones 7.9.x anteriores a la 7.9.2.0 (y Sugar Co... • https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-5946
https://notcve.org/view.php?id=CVE-2015-5946
07 Aug 2017 — Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension. Una vulnerabilidad de lista negra (blacklist) incompleta en SuiteCRM versión 7.2.2, permite a los usuarios autenticados remotos ejecutar código arbitrario al cargar un archivo con una extensión ejecutable. • http://www.openwall.com/lists/oss-security/2015/08/06/6 • CWE-184: Incomplete List of Disallowed Inputs •