CVE-2019-14974
MEDIUMNuclei
SugarCRM Enterprise 9.0.0 - Cross-Site Scripting
Record summary
CVE-2019-14974 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Proofs of concept
2Catalogued exploits
ExploitDBSugarCRM Enterprise 9.0.0 - Cross-Site ScriptingExploitDB exploitby Ilca Lucian FlorinNot analyzed1 file
Repository PoCs
GitHubconan-sudo/CVE-2019-14974-bypassRepository PoCby conan-sudoStars: 4Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMSugarCRM Enterprise 9.0.0 - Cross-Site ScriptingCVSS 6.1
SugarCRM Enterprise 9.0.0 contains a cross-site scripting vulnerability via mobile/error-not-supported-platform.html?desktop_url.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of SugarCRM Enterprise.
WeaknessesCWE-79
Authorsmadrobot
Template tagscvecve2019xsssugarcrmedbvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sugarcrm:sugarcrm:9.0.0:*:*:*:enterprise:*:*:*
Shodan: http.html:"sugarcrm inc. all rights reserved"
Shodan: http.title:sugarcrm
FOFA: body="sugarcrm inc. all rights reserved"
FOFA: title=sugarcrm
Google: intitle:sugarcrm
Google: intext:"sugarcrm inc. all rights reserved"
https://www.exploit-db.com/exploits/47247 https://nvd.nist.gov/vuln/detail/CVE-2019-14974 https://github.com/anonymous364872/Rapier_Tool https://github.com/merlinepedra/nuclei-templates https://github.com/merlinepedra25/nuclei-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-14974 exploit-db.com
https://www.exploit-db.com/exploits/47247