← Back to CVE List

CVE-2018-20816

Published: 2019-04-05T16:29Z
Last Modified: 2024-11-21T04:02Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt