SugarCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-17784 - Vulnerability Database

SugarCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-17784

Medium
Reference: CVE-2018-17784
Title: SugarCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.