First published: Wed Mar 16 2011(Updated: )
SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain duplicate check, which allows remote authenticated users to discover (1) the names of customers via a ShowDuplicates action to the Accounts module, reachable through index.php; or (2) the names of contact persons via a ShowDuplicates action to the Contacts module, reachable through index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | =5.5.2 | |
Sugarcrm Sugarcrm | =1.5d | |
Sugarcrm Sugarcrm | =5.0.0 | |
Sugarcrm Sugarcrm | =4.2.1 | |
Sugarcrm Sugarcrm | =5.5.4 | |
Sugarcrm Sugarcrm | =4.5.0f | |
Sugarcrm Sugarcrm | =1.1a | |
Sugarcrm Sugarcrm | =4.0 | |
Sugarcrm Sugarcrm | =5.2g | |
Sugarcrm Sugarcrm | =5.1c | |
Sugarcrm Sugarcrm | =5.2d | |
Sugarcrm Sugarcrm | =3.5.1 | |
Sugarcrm Sugarcrm | =1.1b | |
Sugarcrm Sugarcrm | =4.0.1 | |
Sugarcrm Sugarcrm | =5.1.0 | |
Sugarcrm Sugarcrm | =5.5-beta2 | |
Sugarcrm Sugarcrm | =4.1 | |
Sugarcrm Sugarcrm | =1.0g | |
Sugarcrm Sugarcrm | =6.1.0 | |
Sugarcrm Sugarcrm | =5.5.1 | |
Sugarcrm Sugarcrm | =6.0 | |
Sugarcrm Sugarcrm | =4.5.1 | |
Sugarcrm Sugarcrm | =4.5.0 | |
Sugarcrm Sugarcrm | =6.1.1 | |
Sugarcrm Sugarcrm | =5.0.0 | |
Sugarcrm Sugarcrm | =6.0.2 | |
Sugarcrm Sugarcrm | =5.0.0 | |
Sugarcrm Sugarcrm | =5.2a | |
Sugarcrm Sugarcrm | =2.0.1c | |
Sugarcrm Sugarcrm | =5.2d | |
Sugarcrm Sugarcrm | <=6.1.2 | |
Sugarcrm Sugarcrm | =5.1.0-beta | |
Sugarcrm Sugarcrm | =4.5.1i | |
Sugarcrm Sugarcrm | =1.1e | |
Sugarcrm Sugarcrm | =2.0.1 | |
Sugarcrm Sugarcrm | =5.2f | |
Sugarcrm Sugarcrm | =3.5 | |
Sugarcrm Sugarcrm | =5.2c | |
Sugarcrm Sugarcrm | =1.1c | |
Sugarcrm Sugarcrm | =6.0.1 | |
Sugarcrm Sugarcrm | =1.1f | |
Sugarcrm Sugarcrm | =5.1l | |
Sugarcrm Sugarcrm | =1.0 | |
Sugarcrm Sugarcrm | =5.2e | |
Sugarcrm Sugarcrm | =5.2h | |
Sugarcrm Sugarcrm | =2.0.1a | |
Sugarcrm Sugarcrm | =5.5a | |
Sugarcrm Sugarcrm | =5.2c | |
Sugarcrm Sugarcrm | =1.1d | |
Sugarcrm Sugarcrm | =3.0.1 | |
Sugarcrm Sugarcrm | =5.2.0g | |
Sugarcrm Sugarcrm | =1.0f | |
Sugarcrm Sugarcrm | =6.0.3 | |
Sugarcrm Sugarcrm | =5.0.0k | |
Sugarcrm Sugarcrm | =5.2e | |
Sugarcrm Sugarcrm | =4.5.1 | |
Sugarcrm Sugarcrm | =4.5.1o | |
Sugarcrm Sugarcrm | =5.5.0 | |
Sugarcrm Sugarcrm | =5.0.0h | |
Sugarcrm Sugarcrm | =5.5-beta1 | |
Sugarcrm Sugarcrm | =1.1 | |
Sugarcrm Sugarcrm | =4.2 | |
Sugarcrm Sugarcrm | =5.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.