Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sugarcrm sugarcrm vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2019-17299
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the Administration module by an Admin user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17300
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the Administration module by a Developer user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17301
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17303
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17304
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17306
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17313
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows directory traversal in the Studio module by a Developer user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17315
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP object injection in the Administration module by an Admin user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17317
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
Sugarcrm Sugarcrm
NA
CVE-2004-1226
SugarCRM Sugar Sales 2.0.1c and previous versions allows remote malicious users to gain sensitive information via certain requests to scripts that contain invalid input, which reveals the path in an error message, as demonstrated using phprint.php with an empty module parameter.
Sugarcrm Sugarcrm
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
logic flaw
CVE-2024-23692
CVE-2024-26229
CVE-2024-35255
CVE-2024-5835
CVE-2024-5837
XML external entity
dos
CVE-2024-5813
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »