CVE-2014-3244

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
01/02/2018
Last modified:
15/02/2018

Description

XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* 6.5.16 (excluding)