Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are not blocked.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SuiteCRM 跨站脚本漏洞
Vulnerability Description
SuiteCRM是SuiteCRM(Suitecrm)团队的一个客户关系管理系统。 SuiteCRM 7.11.19 之前的 Web 界面中存在安全漏洞,该漏洞允许远程攻击者通过绕过内容类型过滤器引入任意 JavaScript 来上传恶意文件。
CVSS Information
N/A
Vulnerability Type
N/A