Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SalesAgility SuiteCRM 跨站脚本漏洞
Vulnerability Description
Salesagility SalesAgility SuiteCRM是英国SalesAgility(Salesagility)公司的一套企业级开源客户关系管理(CRM)。 SalesAgility SuiteCRM 7.8.24之前的7.x版本和7.10.11之前的7.10.x版本中存在跨站脚本漏洞,该漏洞源于WEB应用未充分验证请求是否来自可信用户。攻击者可利用该漏洞通过受影响客户端向服务器发送非预期的请求。
CVSS Information
N/A
Vulnerability Type
N/A