First published: Mon Oct 07 2019(Updated: )
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17308 is a vulnerability in SugarCRM before 8.0.4 and 9.x before 9.0.2 that allows PHP code injection in the Emails module by a regular user.
CVE-2019-17308 has a severity rating of 8.8 (high).
CVE-2019-17308 affects SugarCRM versions between 7.9.0.0 and 7.9.5.0 (Enterprise and Professional editions), between 8.0.0 and 8.0.4 (Enterprise, Professional, and Ultimate editions), and between 9.0.0 and 9.0.2 (Enterprise, Professional, and Ultimate editions).
To fix CVE-2019-17308, upgrade your SugarCRM installation to version 8.0.4 or 9.0.2, depending on your current version.
More information about CVE-2019-17308 can be found at the following link: [https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-035/](https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-035/)