An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/salesagility/SuiteDocs/pull/198/files | third party advisory patch |
https://docs.suitecrm.com/admin/releases/7.10.x/#_7_10_11 | release notes vendor advisory |
https://docs.suitecrm.com/admin/releases/7.8.x/#_7_8_24 | release notes vendor advisory |