First published: Mon Oct 07 2019(Updated: )
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by an Admin user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17292 is a vulnerability in SugarCRM before version 8.0.4 and 9.x before 9.0.2 that allows SQL injection in the pmse_Inbox module by an Admin user.
CVE-2019-17292 has a severity score of 7.2 (high).
The affected software versions include SugarCRM Enterprise versions between 7.9.0.0 and 7.9.5.0, SugarCRM Enterprise versions between 8.0.0 and 8.0.4, SugarCRM Enterprise versions between 9.0.0 and 9.0.2, SugarCRM Professional versions between 7.9.0.0 and 7.9.5.0, SugarCRM Professional versions between 8.0.0 and 8.0.4, and SugarCRM Professional versions between 9.0.0 and 9.0.2.
To fix CVE-2019-17292, you should upgrade your SugarCRM installation to version 8.0.4 or 9.0.2 depending on the edition you are using.
You can find more information about CVE-2019-17292 on the SugarCRM website: https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-019/