VulnerabilityModified
CVE-2018-20816
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking.
MEDIUM 6.1EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-352
- Affected
- salesagility/suitecrm
- Source
- cve@mitre.org
References
- https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_11Release Notes, Vendor Advisory
- https://docs.suitecrm.com/admin/releases/7.8.x/#_7_8_24Release Notes, Vendor Advisory
- https://github.com/salesagility/SuiteDocs/pull/198/filesPatch, Third Party Advisory
- https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_11Release Notes, Vendor Advisory
- https://docs.suitecrm.com/admin/releases/7.8.x/#_7_8_24Release Notes, Vendor Advisory
- https://github.com/salesagility/SuiteDocs/pull/198/filesPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.