S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-14974 Scanner

CVE-2019-14974 scanner - Cross-Site Scripting (XSS) vulnerability in SugarCRM Enterprise

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-14974
6.1
CVSS

SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

SugarCRM Enterprise is a software solution designed to help businesses manage customer relationships, streamline sales processes, and increase overall productivity. The platform offers a range of features and tools, like customer analytics, sales automation, and marketing campaigns, all designed to help users drive business growth and maximize their ROI. The platform is widely used by businesses of all sizes, operating across various industries, for its user-friendly interface, customizability, and ability to integrate with other business solutions.

However, despite its many benefits, SugarCRM Enterprise 9.0.0 has been found to contain a critical security flaw in the form of an XSS vulnerability. Leveraging the CVE-2019-14974 vulnerability code, cybercriminals could exploit the software by injecting malicious code into web pages viewed by users, ultimately leading to the stealing of sensitive user data, hijacking of user accounts, and the execution of unauthorized commands.

Once exploited, the vulnerability can wreak havoc on a businesses' digital infrastructure, resulting in numerous serious consequences. For instance, cybercriminals can leverage the vulnerability to gain access to sensitive information, including user credentials, business contacts, and financial data. They could also alter web pages, redirect users to malicious websites, or inject harmful scripts into web pages - all leading to loss of trust, financial losses, and reputational damage.

Finally, s4e.io is a platform well-known for its pro features. They provide expert analysis and data-driven insights on vulnerabilities in digital assets that businesses can leverage to make informed decisions and protect their digital infrastructures. With this platform, those who read this article can quickly and easily learn about vulnerabilities in their digital solutions and take the necessary steps to mitigate them.

 

REFERENCES

Solution Advice

To protect against the CVE-2019-14974 vulnerability and other similar threats, businesses that use SugarCRM Enterprise should take the necessary precautions. Here are a few ways to do this, such as:

  • Update the software to the latest version that includes a fix for the vulnerability.
  • Implement access control measures for user accounts and set strict password policies.
  • Regularly monitor system logs and web page activity for suspicious behavior.
  • Use multi-factor authentication to ensure only authorized users can access the platform.
  • Install anti-virus and anti-malware tools for real-time protection against malicious threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-14974 scanner - Cross-Site Scripting (XSS) vulnerability in SugarCRM Enterprise S4E