CVE-2018-5715: SugarCRM

Medium severity, CVSS 6.1. EPSS: 6.9% chance of exploitation in the next 30 days.

phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).

Affected products

Published 2018-01-16. Last modified 2026-06-17.