First published: Wed Aug 12 2020(Updated: )
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | <10.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-17373 is medium with a CVSS score of 5.3.
CVE-2020-17373 affects SugarCRM versions before 10.1.0 (Q3 2020) and allows SQL Injection.
SQL Injection is a code injection technique that attackers use to exploit vulnerabilities in a website's database layer, allowing them to perform unauthorized actions such as retrieving, modifying, or deleting data.
The Common Weakness Enumeration (CWE) for CVE-2020-17373 is CWE-89 (SQL Injection).
To fix the SQL Injection vulnerability in SugarCRM, update to version 10.1.0 (Q3 2020) or later.