PT-2023-25325 · Sugarcrm · Sugarcrm Enterprise

Egidio Romano

·

Published

2023-06-17

·

Updated

2024-12-17

·

CVE-2023-35808

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SugarCRM Enterprise versions prior to 11.0.6 SugarCRM Enterprise versions 12.x prior to 12.0.3
Description An Unrestricted File Upload issue has been identified in the Notes module due to missing input validation. This allows custom PHP code to be injected and executed through crafted requests, using regular user privileges. The issue affects not only Enterprise editions but also other editions.
Recommendations For SugarCRM Enterprise versions prior to 11.0.6, update to version 11.0.6 or later to resolve the issue. For SugarCRM Enterprise versions 12.x prior to 12.0.3, update to version 12.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Notes module until a patch is applied.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-35808

Affected Products

Sugarcrm Enterprise