Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sugarcrm sugarcrm vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2019-17309
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17310
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17312
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows directory traversal in the file function by a Regular user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17315
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP object injection in the Administration module by an Admin user.
Sugarcrm Sugarcrm
7.2
CVSSv3
CVE-2019-17317
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17319
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the Emails module by a Regular user.
Sugarcrm Sugarcrm
9.8
CVSSv3
CVE-2012-0694
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote malicious users to execute arbitrary PHP code.
Sugarcrm Sugarcrm
2 EDB exploits
9.8
CVSSv3
CVE-2014-3244
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM prior to 6.5.17 allows remote malicious users to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17294
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the export function by a Regular user.
Sugarcrm Sugarcrm
8.8
CVSSv3
CVE-2019-17297
SugarCRM prior to 8.0.4 and 9.x prior to 9.0.2 allows SQL injection in the Quotes module by a Regular user.
Sugarcrm Sugarcrm
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
man-in-the-middle
command injection
CVE-2021-47511
CVE-2024-26238
CVE-2024-4858
CVE-2024-21305
XXE
CVE-2021-47555
CVE-2021-47526
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »