Description
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
Remediation
References
Related Vulnerabilities
Drupal Core 9.4.x Remote Code Execution (9.4.0 - 9.4.2)
WordPress Plugin Newsletter-Send awesome emails from WordPress SQL Injection (3.0.8)
WordPress Plugin Connector for Gravity Forms and Google Sheets Cross-Site Scripting (1.1.0)
ReviveAdserver Deserialization of Untrusted Data Vulnerability (CVE-2017-5830)