Description
Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.
Remediation
References
Related Vulnerabilities
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-41308)
WordPress 4.5.x Same Origin Method Execution (SOME) Vulnerability (4.5 - 4.5.1)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2101)
MySQL CVE-2024-21238 Vulnerability (CVE-2024-21238)
WordPress Plugin Images to WebP Multiple Vulnerabilities (1.8)