CVE-2023-3293

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*

History

22 Jun 2023, 21:30

Type Values Removed Values Added
References (CONFIRM) https://huntr.dev/bounties/22cb0ee3-e5da-40e0-9d2c-ace9b759f171 - (CONFIRM) https://huntr.dev/bounties/22cb0ee3-e5da-40e0-9d2c-ace9b759f171 - Exploit, Patch, Third Party Advisory
References (MISC) https://github.com/salesagility/suitecrm-core/commit/1f949f1ac2b7fe82f3c2c6071f842b804ba91929 - (MISC) https://github.com/salesagility/suitecrm-core/commit/1f949f1ac2b7fe82f3c2c6071f842b804ba91929 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CPE cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*
First Time Salesagility
Salesagility suitecrm

16 Jun 2023, 12:47

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-16 11:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-3293

Mitre link : CVE-2023-3293

CVE.ORG link : CVE-2023-3293


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')