CVE-2010-0465
Sugarcrm - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the online Documents functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a allows remote authenticated users to inject arbitrary web script or HTML via the Document Name field.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.6%
Classification
CWE
CWE-79
Status
published
Affected Products (12)
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
n/a/n/a
Timeline
Published
Mar 19, 2010
Tracked Since
Feb 18, 2026