PT-2023-25325 · Sugarcrm · Sugarcrm Enterprise
Egidio Romano
·
Published
2023-06-17
·
Updated
2024-12-17
·
CVE-2023-35808
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SugarCRM Enterprise versions prior to 11.0.6
SugarCRM Enterprise versions 12.x prior to 12.0.3
Description
An Unrestricted File Upload issue has been identified in the Notes module due to missing input validation. This allows custom PHP code to be injected and executed through crafted requests, using regular user privileges. The issue affects not only Enterprise editions but also other editions.
Recommendations
For SugarCRM Enterprise versions prior to 11.0.6, update to version 11.0.6 or later to resolve the issue.
For SugarCRM Enterprise versions 12.x prior to 12.0.3, update to version 12.0.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Notes module until a patch is applied.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sugarcrm Enterprise