CVE-2023-6128
MEDIUMGitHub salesagility/suitecrm <7.14.2-8.4.2 - XSS
Title source: llmDescription
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Exploits (1)
Scores
CVSS v3
5.4
EPSS
0.0016
EPSS Percentile
36.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (5)
salesagility/suitecrm
7.14.0
salesagility/suitecrm
7.14.1
salesagility/suitecrm
8.4.0
salesagility/suitecrm
8.4.1
salesagility/suitecrm
< 7.12.14
Published
Nov 14, 2023
Tracked Since
Feb 18, 2026