CVE-2020-36501
Last modified
CVE-2020-36501 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sugarcrm | Sugarcrm | 6.5.18 |
References
- https://www.vulnerability-lab.com/get_content.php?id=2249Exploit, Third Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2249Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-36501?
How severe is CVE-2020-36501?
How do I fix CVE-2020-36501?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-36494DedeCMS v7.5 SP2 was discovered to contain multiple cross-si…6.1
- CVE-2020-36495DedeCMS v7.5 SP2 was discovered to contain multiple cross-si…6.1
- CVE-2020-36496DedeCMS v7.5 SP2 was discovered to contain multiple cross-si…6.1
- CVE-2020-36497DedeCMS v7.5 SP2 was discovered to contain multiple cross-si…6.1
- CVE-2020-36498Macrob7 Macs Framework Content Management System - 1.14f con…5.4
- CVE-2020-36499TAO Open Source Assessment Platform v3.3.0 RC02 was discover…5.4
- CVE-2020-36502Swift File Transfer Mobile v1.1.2 was discovered to contain …6.1
- CVE-2020-36503The Connections Business Directory WordPress plugin before 9…8
- CVE-2020-36504The WP-Pro-Quiz WordPress plugin through 0.37 does not have …6.5
- CVE-2020-36505The Delete All Comments Easily WordPress plugin through 1.3 …6.5
- CVE-2020-3651Active command timeout since WM status change cmd is not rem…7.5
- CVE-2020-36510The 15Zine WordPress theme before 3.3.0 does not sanitise an…6.1
Are you affected by CVE-2020-36501?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
