PT-2019-6725 · Sugarcrm · Sugarcrm Ce
Egidio Romano
+1
·
Published
2019-10-29
·
Updated
2019-11-01
·
CVE-2012-0694
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SugarCRM CE versions 6.3.1 and earlier
Description
The issue allows remote attackers to execute arbitrary PHP code due to the use of
unserialize() with user-controlled input in certain scripts.Recommendations
For SugarCRM CE versions 6.3.1 and earlier, as a temporary workaround, consider restricting access to the affected scripts that utilize
unserialize() with user-controlled input until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sugarcrm Ce