Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sugarcrm sugarcrm vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-2460
Sugar Suite Open Source (SugarCRM) 4.2 and previous versions, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote malicious users to conduct attacks such as directory traversal or PHP remote ...
Sugarcrm Sugarcrm 3.5
Sugarcrm Sugarcrm 4.0
Sugarcrm Sugarcrm 4.1
Sugarcrm Sugarcrm 4.2
1 EDB exploit
8.8
CVSSv3
CVE-2023-46815
An issue exists in SugarCRM 12 prior to 12.0.4 and 13 prior to 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using a crafted request, custom PHP code can be injected via the Notes module because of missing input validation. An attac...
Sugarcrm Sugarcrm 13.0.0
Sugarcrm Sugarcrm 13.0.1
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2023-46816
An issue exists in SugarCRM 12 prior to 12.0.4 and 13 prior to 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing inpu...
Sugarcrm Sugarcrm 13.0.0
Sugarcrm Sugarcrm 13.0.1
Sugarcrm Sugarcrm
NA
CVE-2008-2045
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote malicious users to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds ...
Sugarcrm Sugarcrm 4.5.1
Sugarcrm Sugarcrm 5.0.0
1 EDB exploit
NA
CVE-2006-5082
Unspecified vulnerability in Sugar Suite Open Source (SugarCRM) prior to 4.2.1 Patch C (20060917) has unspecified impact, related to code execution, and unspecified attack vectors.
Sugarcrm Sugar Suite 4.1
Sugarcrm Sugar Suite 4.2
Sugarcrm Sugar Suite 4.2.1
Sugarcrm Sugar Suite 4.0.1
Sugarcrm Sugar Suite 4.0 Beta
Sugarcrm Sugar Suite 3.5
Sugarcrm Sugar Suite 3.5.1
7.2
CVSSv3
CVE-2019-17292
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the pmse_Inbox module by an Admin user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17293
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17295
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the history function by a Regular user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17296
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the Contacts module by a Regular user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17298
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the Administration module by a Developer user.
Sugarcrm Sugarcrm
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5274
CVE-2024-35388
CVE-2024-35396
elevation of privilege
CVE-2021-47544
file upload
CVE-2021-47545
memory leak
CVE-2024-4956
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »