PT-2017-13495 · Sugarcrm · Sugar Community Edition+1

Published

2017-09-17

·

Updated

2017-12-30

·

CVE-2017-14509

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SugarCRM versions prior to 7.7.2.3 SugarCRM versions 7.8.x prior to 7.8.2.2 SugarCRM versions 7.9.x prior to 7.9.2.0 Sugar Community Edition version 6.5.26
Description A remote file inclusion issue has been identified in the Connectors module, allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string. This issue has been mitigated by adding proper input validation.
Recommendations For SugarCRM versions prior to 7.7.2.3, update to version 7.7.2.3 or later. For SugarCRM versions 7.8.x prior to 7.8.2.2, update to version 7.8.2.2 or later. For SugarCRM versions 7.9.x prior to 7.9.2.0, update to version 7.9.2.0 or later. For Sugar Community Edition version 6.5.26, consider upgrading to a later version to mitigate the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14509

Affected Products

Sugar Community Edition
Sugarcrm