Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SuiteCRM 跨站脚本漏洞
Vulnerability Description
SuiteCRM是SuiteCRM(Suitecrm)团队的一个客户关系管理系统。 SuiteCRM 中存在跨站脚本漏洞,该漏洞源于产品的 clean_file_output 保护机制未对SVG文件上传做有效验证。攻击者可通过该漏洞执行客户端脚本。以下产品及版本受到影响:SuiteCRM 7.11.19之前版本。
CVSS Information
N/A
Vulnerability Type
N/A