SugarCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-5715 - Vulnerability Database

SugarCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-5715

Medium
Reference: CVE-2018-5715
Title: SugarCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a key variable).