2024-12-08 03:06:42 +00:00

158 lines
5.3 KiB
JSON

{
"id": "CVE-2010-0465",
"sourceIdentifier": "cve@mitre.org",
"published": "2010-03-19T19:30:00.453",
"lastModified": "2024-11-21T01:12:16.613",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the online Documents functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a allows remote authenticated users to inject arbitrary web script or HTML via the Document Name field."
},
{
"lang": "es",
"value": "Vulnerabilidad de ejecuci\u00f3n de secuencias de comandos en sitios cruzados (XSS) en la funcionalidad de documentos en l\u00ednea en SugarCRM v5.2.x anterior a v5.2.0l y v5.5.x anterior a v5.5.0a permite a usuarios autenticados remotamente inyectar secuencias de comandos web o HTML de su elecci\u00f3n a trav\u00e9s del campo \"Document Name\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2.0g:*:*:*:*:*:*:*",
"matchCriteriaId": "699A9586-0683-4DAA-9E5C-662C0630C6EF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2a:*:*:*:*:*:*:*",
"matchCriteriaId": "439E75C4-C02D-4905-9D73-CE27D6A54C5A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2c:*:*:*:*:*:*:*",
"matchCriteriaId": "6BF95EA0-16E7-4173-AEC8-D66A3F8FB62B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2d:*:*:*:*:*:*:*",
"matchCriteriaId": "BFA524F8-A78F-414A-A5AC-1A89901BD917"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2e:*:*:*:*:*:*:*",
"matchCriteriaId": "CFCC9802-4642-4331-9D56-4E1F76151E24"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2f:*:*:*:*:*:*:*",
"matchCriteriaId": "7922DB4E-9812-4636-A61D-8D201CE92D93"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2g:*:*:*:*:*:*:*",
"matchCriteriaId": "57A8ECCF-AAEC-49B1-B474-E4DD14EE7CF3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.2h:*:*:*:*:*:*:*",
"matchCriteriaId": "5AC18299-07B6-46BB-93DF-E642FE637395"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.5:beta1:*:*:*:*:*:*",
"matchCriteriaId": "B1E9C26A-6845-45C3-A801-E5F1B5B9B0E5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.5:beta2:*:*:*:*:*:*",
"matchCriteriaId": "EF6C4B76-D1CD-4B58-A9FF-5D35EEAC89EA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sugarcrm:sugarcrm:5.5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "3943C856-B008-4E66-802B-762D28B679A6"
}
]
}
]
}
],
"references": [
{
"url": "http://secunia.com/advisories/38962",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/510116/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/38772",
"source": "cve@mitre.org"
},
{
"url": "http://www.sugarcrm.com/crm/support/bugs.html?task=view&caseID=db4489b7-b5a8-4a6d-555b-4b9ffa7b4ffa",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/38962",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/510116/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/38772",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sugarcrm.com/crm/support/bugs.html?task=view&caseID=db4489b7-b5a8-4a6d-555b-4b9ffa7b4ffa",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}