Medium severity6.1NVD Advisory· Published Aug 18, 2021· Updated Jun 17, 2026
CVE-2021-39267
CVE-2021-39267
Description
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are not blocked.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- SuiteCRM/SuiteCRMdescription
Patches
Vulnerability mechanics
References
2- thanhlocpanda.wordpress.com/2021/07/31/file-upload-bypass-suitecrm-7-11-18/nvdExploitThird Party Advisory
- docs.suitecrm.com/admin/releases/7.11.x/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.