« Back to list

CVE-2017-14510

Status: ModifiedMedium (6.1)—

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This attack vector is mitigated by proper validating the redirect URL values being passed along.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-14510",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-17T21:29:00.327",
  "references": [
    {
      "url": "https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2017-008/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.synology.com/support/security/Synology_SA_17_53_SugarCRM",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2017-008/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.synology.com/support/security/Synology_SA_17_53_SugarCRM",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This attack vector is mitigated by proper validating the redirect URL values being passed along."
    },
    {
      "lang": "es",
      "value": "Existe un problema en SugarCRM en versiones anteriores a la 7.7.2.3, en versiones 7.8.x anteriores a la 7.8.2.2 y en versiones 7.9.x anteriores a la 7.9.2.0 (y Sugar Community Edition 6.5.26). La funcionalidad WebToLeadCapture es vulnerable a ataques Cross-Site Scripting (XSS) no autenticados. Este vector de ataque se mitiga mediante la correcta validación de los valores de redirección URL que se van pasando."
    }
  ],
  "lastModified": "2026-06-17T01:06:17.360",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CF7DEB0-D9C7-4422-8632-F70D7EE23DB9",
              "versionEndIncluding": "7.7.2.2"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:6.5.26:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3E99EB2-05BF-4575-9170-D9014B2D6B5A"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.8.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD5EB33E-9B9E-4D05-928E-55D53F94A698"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.8.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62260AB3-77B6-4E7D-9ECF-AB0871F01E52"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.8.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B59B76F-5141-47BE-975D-356742C13659"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.8.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F20AB20-1C40-4192-8B1D-0C227681F2EE"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.8.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2021DD4C-B55B-4C52-B46B-C71AE71E1B48"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.9.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6A722A2-2DD7-4513-85B2-5DE2886D1AC2"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.9.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D34FE48A-1DA0-4F87-9C62-507123D070AA"
            },
            {
              "criteria": "cpe:2.3:a:sugarcrm:sugarcrm:7.9.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DA7C251-86A8-4B1C-9296-C6008CAF65DF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}