CVE-2018-5715: SugarCRM
Medium severity, CVSS 6.1. EPSS: 6.9% chance of exploitation in the next 30 days.
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
Affected products
- SugarCRM SugarCRM: version 3.5.1 only
Published 2018-01-16. Last modified 2026-06-17.