CVE-2018-17784

MEDIUM

SugarCRM Community Edition 6.5.26 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-17784. PoCs published by Purplemet Security.

AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in SugarCRM Community Edition 6.5.26 via malformed parameters in SWF files. The PoC URLs inject JavaScript code to trigger an alert, confirming the XSS vulnerability.

Description

Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

Exploits (1)

exploitdb WORKING POC
by Purplemet Security · textwebappsphp
https://www.exploit-db.com/exploits/45594

This exploit demonstrates a cross-site scripting (XSS) vulnerability in SugarCRM Community Edition 6.5.26 via malformed parameters in SWF files. The PoC URLs inject JavaScript code to trigger an alert, confirming the XSS vulnerability.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SugarCRM Community Edition 6.5.26
No auth needed
Prerequisites: Access to the target SugarCRM instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
https://twitter.com/purplemet/status/1043979681186369537
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45594/

Scores

CVSS v3 6.1
EPSS 0.0435
EPSS Percentile 90.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
sugarcrm/sugarcrm 6.5.0 - 6.5.26
Published Oct 10, 2018
Tracked Since Feb 18, 2026