CVE-2010-0465

Sugarcrm - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the online Documents functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a allows remote authenticated users to inject arbitrary web script or HTML via the Document Name field.

Scores

EPSS 0.0029
EPSS Percentile 51.6%

Classification

CWE
CWE-79
Status published

Affected Products (12)

sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
sugarcrm/sugarcrm
n/a/n/a

Timeline

Published Mar 19, 2010
Tracked Since Feb 18, 2026