Back
CVE-2014-3244
CRITICAL
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Published: Feb 1, 2018
Modified: Jun 17, 2026
CWE-611
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| sugarcrm | sugarcrm | * < 6.5.16 |
GitHub Security Advisory GHSA-7wgc-prfc-r69w
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17...
References (6)
- http://seclists.org/fulldisclosure/2014/Jun/92 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68102 Third Party Advisory, VDB Entry
- https://web.archive.org/web/20151105182132/http://www.pnigos.com/?p=294 Exploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Jun/92 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68102 Third Party Advisory, VDB Entry
- https://web.archive.org/web/20151105182132/http://www.pnigos.com/?p=294 Exploit, Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
5.04%
Top 8% most likely to be exploited
Threat Score
40.7 / 100
Data Sources
NVD
EPSS
GitHub