A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "7.10.35"
},
{
"fixed": "7.10.35"
},
{
"introduced": "7.11.0"
},
{
"fixed": "7.12.2"
},
{
"introduced": "7.11.0"
},
{
"fixed": "7.12.2"
}
],
"vendor_product": "salesagility:suitecrm",
"source": "CPE_RANGE"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.10.35"
},
{
"introduced": "7.12.x"
},
{
"fixed": "7.12.2"
}
],
"source": "DESCRIPTION"
}