Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-02727
HistoryDec 29, 2021 - 12:00 a.m.

SuiteRM Cross-Site Scripting Vulnerability

2021-12-2900:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
suitecrm
cross-site scripting
vulnerability
security
javascript
attachment upload

EPSS

0.003

Percentile

70.3%

SuiteCRM is a customer relationship management system from the SuiteCRM (Suitecrm) team.SuiteCRM versions prior to 7.10.35, 7.11.x, and 7.12.x prior to 7.12.2 have a security vulnerability that could be exploited by an attacker to introduce arbitrary JavaScript via attachment upload.

EPSS

0.003

Percentile

70.3%

Related for CNVD-2022-02727