CVE-2017-14510
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This attack vector is mitigated by proper validating the redirect URL values being passed along.
Existe un problema en SugarCRM en versiones anteriores a la 7.7.2.3, en versiones 7.8.x anteriores a la 7.8.2.2 y en versiones 7.9.x anteriores a la 7.9.2.0 (y Sugar Community Edition 6.5.26). La funcionalidad WebToLeadCapture es vulnerable a ataques Cross-Site Scripting (XSS) no autenticados. Este vector de ataque se mitiga mediante la correcta validación de los valores de redirección URL que se van pasando.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-09-17 CVE Reserved
- 2017-09-17 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.synology.com/support/security/Synology_SA_17_53_SugarCRM | X_refsource_confirm |
|
URL | Date | SRC |
---|---|---|
https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2017-008 | 2017-12-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | <= 7.7.2.2 Search vendor "Sugarcrm" for product "Sugarcrm" and version " <= 7.7.2.2" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 6.5.26 Search vendor "Sugarcrm" for product "Sugarcrm" and version "6.5.26" | community |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.8.0.0 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.8.0.0" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.8.0.1 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.8.0.1" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.8.1.0 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.8.1.0" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.8.2.0 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.8.2.0" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.8.2.1 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.8.2.1" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.9.0.0 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.9.0.0" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.9.0.1 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.9.0.1" | - |
Affected
| ||||||
Sugarcrm Search vendor "Sugarcrm" | Sugarcrm Search vendor "Sugarcrm" for product "Sugarcrm" | 7.9.1.0 Search vendor "Sugarcrm" for product "Sugarcrm" and version "7.9.1.0" | - |
Affected
|