First published: Wed Mar 16 2011(Updated: )
SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the Accounts module, reachable through index.php; or (2) the names of contact persons via a ShowDuplicates action to the Contacts module, reachable through index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SugarCRM | =5.5.2 | |
SugarCRM | =1.5d | |
SugarCRM | =5.0.0 | |
SugarCRM | =4.2.1 | |
SugarCRM | =5.5.4 | |
SugarCRM | =4.5.0f | |
SugarCRM | =1.1a | |
SugarCRM | =4.0 | |
SugarCRM | =5.2g | |
SugarCRM | =5.1c | |
SugarCRM | =5.2d | |
SugarCRM | =3.5.1 | |
SugarCRM | =1.1b | |
SugarCRM | =4.0.1 | |
SugarCRM | =5.1.0 | |
SugarCRM | =5.5-beta2 | |
SugarCRM | =4.1 | |
SugarCRM | =1.0g | |
SugarCRM | =6.1.0 | |
SugarCRM | =5.5.1 | |
SugarCRM | =6.0 | |
SugarCRM | =4.5.1 | |
SugarCRM | =4.5.0 | |
SugarCRM | =6.1.1 | |
SugarCRM | =5.0.0 | |
SugarCRM | =6.0.2 | |
SugarCRM | =5.0.0 | |
SugarCRM | =5.2a | |
SugarCRM | =2.0.1c | |
SugarCRM | =5.2d | |
SugarCRM | <=6.1.2 | |
SugarCRM | =5.1.0-beta | |
SugarCRM | =4.5.1i | |
SugarCRM | =1.1e | |
SugarCRM | =2.0.1 | |
SugarCRM | =5.2f | |
SugarCRM | =3.5 | |
SugarCRM | =5.2c | |
SugarCRM | =1.1c | |
SugarCRM | =6.0.1 | |
SugarCRM | =1.1f | |
SugarCRM | =5.1l | |
SugarCRM | =1.0 | |
SugarCRM | =5.2e | |
SugarCRM | =5.2h | |
SugarCRM | =2.0.1a | |
SugarCRM | =5.5a | |
SugarCRM | =5.2c | |
SugarCRM | =1.1d | |
SugarCRM | =3.0.1 | |
SugarCRM | =5.2.0g | |
SugarCRM | =1.0f | |
SugarCRM | =6.0.3 | |
SugarCRM | =5.0.0k | |
SugarCRM | =5.2e | |
SugarCRM | =4.5.1 | |
SugarCRM | =4.5.1o | |
SugarCRM | =5.5.0 | |
SugarCRM | =5.0.0h | |
SugarCRM | =5.5-beta1 | |
SugarCRM | =1.1 | |
SugarCRM | =4.2 | |
SugarCRM | =5.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0745 is considered a medium severity vulnerability as it allows authenticated users to obtain sensitive information.
To fix CVE-2011-0745, upgrade to SugarCRM version 6.1.3 or later.
CVE-2011-0745 affects multiple versions of SugarCRM prior to 6.1.3.
CVE-2011-0745 may expose customer names through the ShowDuplicates action in the Accounts module.
Yes, CVE-2011-0745 can be exploited by remote authenticated users.