First published: Sat Jun 17 2023(Updated: )
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be injected and executed through the Notes module because of missing input validation. Regular user privileges can be used to exploit this vulnerability. Editions other than Enterprise are also affected.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | >=11.0.0<11.0.6 | |
Sugarcrm Sugarcrm | >=11.0.0<11.0.6 | |
Sugarcrm Sugarcrm | >=11.0.0<11.0.6 | |
Sugarcrm Sugarcrm | >=11.0.0<11.0.6 | |
Sugarcrm Sugarcrm | >=11.0.0<11.0.6 | |
Sugarcrm Sugarcrm | >=12.0.0<12.0.3 | |
Sugarcrm Sugarcrm | >=12.0.0<12.0.3 | |
Sugarcrm Sugarcrm | >=12.0.0<12.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-35808.
The severity of CVE-2023-35808 is high with a CVSS score of 8.8.
SugarCRM Enterprise versions before 11.0.6 and 12.x before 12.0.3 are affected by CVE-2023-35808.
CVE-2023-35808 is an Unrestricted File Upload vulnerability in the Notes module of SugarCRM Enterprise. Attackers can inject and execute custom PHP code through crafted requests.
Yes, patches or updates are available for CVE-2023-35808. Please refer to the official SugarCRM support website for more information.