Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-17784. PoCs published by Purplemet Security.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SugarCRM Community Edition 6.5.26 via malformed parameters in SWF files. The PoC URLs inject JavaScript code to trigger an alert, confirming the XSS vulnerability.
Description
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in SugarCRM Community Edition 6.5.26 via malformed parameters in SWF files. The PoC URLs inject JavaScript code to trigger an alert, confirming the XSS vulnerability.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N