First published: Mon Oct 07 2019(Updated: )
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17310 is a vulnerability that allows PHP code injection in the Campaigns module of SugarCRM before 8.0.4 and 9.x before 9.0.2 by an Admin user.
CVE-2019-17310 has a severity rating of 7.2 (high), and it allows PHP code injection in the Campaigns module, potentially compromising the security of SugarCRM.
CVE-2019-17310 affects SugarCRM versions 7.9.0.0 to 7.9.5.0, 8.0.0 to 8.0.4, and 9.0.0 to 9.0.2 (Enterprise, Professional, and Ultimate editions).
To fix the CVE-2019-17310 vulnerability in SugarCRM, it is recommended to upgrade to version 8.0.4 or 9.0.2 (or higher) and follow the recommendations provided by SugarCRM in their security advisory.
You can find more information about CVE-2019-17310 in the SugarCRM security advisory available at the following link: [https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-037/](https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-037/)