First published: Mon Oct 07 2019(Updated: )
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 | |
Sugarcrm Sugarcrm | >=7.9.0.0<7.9.5.0 | |
Sugarcrm Sugarcrm | >=8.0.0<8.0.4 | |
Sugarcrm Sugarcrm | >=9.0.0<9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17319 is a vulnerability in SugarCRM that allows SQL injection in the Emails module by a regular user.
Versions between 7.9.0.0 and 7.9.5.0 for the Enterprise, Professional, and Ultimate editions of SugarCRM, versions between 8.0.0 and 8.0.4 for the Enterprise, Professional, and Ultimate editions, and versions between 9.0.0 and 9.0.2 for the Enterprise, Professional, and Ultimate editions are affected.
CVE-2019-17319 has a severity rating of 8.8 (high).
To fix CVE-2019-17319, it is recommended to upgrade to version 8.0.4 or 9.0.2 of SugarCRM.
You can find more information about CVE-2019-17319 at the following reference: [https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-047/](https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-047/)