Medium severity6.1NVD Advisory· Published Aug 18, 2021· Updated Jun 17, 2026
CVE-2021-39268
CVE-2021-39268
Description
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- SuiteCRM/SuiteCRMdescription
Patches
Vulnerability mechanics
References
2- thanhlocpanda.wordpress.com/2021/07/31/stored-xss-via-svg-on-suitecrm/nvdExploitThird Party Advisory
- docs.suitecrm.com/admin/releases/7.11.x/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.