CVE-2021-31792
MEDIUMCVSS 5.4/10EPSS 0.87%
Last modified
CVE-2021-31792 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Salesagility | Suitecrm | < 7.11.19 |
References
- https://chris-forbes.github.io/CVE-2021-31792Exploit, Third Party Advisory
- https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_19Release Notes, Vendor Advisory
- https://github.com/salesagility/SuiteCRMRelease Notes, Third Party Advisory
- https://chris-forbes.github.io/CVE-2021-31792Exploit, Third Party Advisory
- https://docs.suitecrm.com/admin/releases/7.11.x/#_7_11_19Release Notes, Vendor Advisory
- https://github.com/salesagility/SuiteCRMRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31792?
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
How severe is CVE-2021-31792?
CVE-2021-31792 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 0.87% probability of exploitation in the next 30 days.
How do I fix CVE-2021-31792?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31784An out-of-bounds write vulnerability exists in the file-read…7.8
- CVE-2021-31785The Bluetooth Classic implementation on Actions ATS2815 and …6.5
- CVE-2021-31786The Bluetooth Classic Audio implementation on Actions ATS281…6.5
- CVE-2021-31787The Bluetooth Classic implementation on Actions ATS2815 chip…6.5
- CVE-2021-3179GGLocker iOS application, contains an insecure data storage …5.5
- CVE-2021-31791In Hardware Sentry KM before 10.0.01 for BMC PATROL, a clear…7.5
- CVE-2021-31793An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 dev…7.5
- CVE-2021-31794Settings.aspx?view=About in Directum 5.8.2 allows XSS via th…6.1
- CVE-2021-31795The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04…7
- CVE-2021-31796An inadequate encryption vulnerability discovered in CyberAr…7.5
- CVE-2021-31797The user identification mechanism used by CyberArk Credentia…5.1
- CVE-2021-31798The effective key space used to encrypt the cache in CyberAr…4.4
Are you affected by CVE-2021-31792?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
