EIP-2026-112472
PRE-CVESugarCRM 6.5.18 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112472. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in SugarCRM 6.5.18, where malicious script code can be injected into the 'Primary Address State' and 'Alternate Address State' fields. The payload executes when a privileged user views the contact, potentially leading to session hijacking or phishing.
Description
SugarCRM 6.5.18 - Persistent Cross-Site Scripting
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in SugarCRM 6.5.18, where malicious script code can be injected into the 'Primary Address State' and 'Alternate Address State' fields. The payload executes when a privileged user views the contact, potentially leading to session hijacking or phishing.