Vulnerabilities
Vulnerable Software
Sugarcrm:  >> Sugarcrm  >> 9.0.2  Security Vulnerabilities
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).
CVSS Score
9.8
EPSS Score
0.012
Published
2020-11-12
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
CVSS Score
5.4
EPSS Score
0.005
Published
2020-08-12
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
CVSS Score
5.3
EPSS Score
0.012
Published
2020-08-12


Contact Us

Shodan ® - All rights reserved