Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sugarcrm HIGH 7.2
CVE-2019-17309

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17310

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17293

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17294

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the export function by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17295

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17296

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17292

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17318

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17319

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17317

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 8.8
CVE-2019-17316

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm HIGH 7.2
CVE-2019-17315

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.

Fix: 7.9.5.0 / 8.0.4+
Fix from $1,950 2019-10-07
Sugarcrm MEDIUM 6.1
CVE-2019-14974EPSS 28%

SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.

No fix yet
Fix from $1,600 2019-08-14
Sugarcrm MEDIUM 6.1
CVE-2018-17784

Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to cond…

Fix: after 6.5.26
Fix from $1,600 2018-10-10
Sugarcrm CRITICAL 9.8
CVE-2014-3244EPSS 5%

XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potent…

Fix: 6.5.16+
Fix from $2,300 2018-02-01
Sugarcrm CRITICAL 9.8
CVE-2018-6308

Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Cam…

No fix yet
Fix from $2,300 2018-01-25
Sugarcrm MEDIUM 6.1
CVE-2018-5715EPSS 7%

phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).

No fix yet
Fix from $1,600 2018-01-16
Sugarcrm HIGH 8.8
CVE-2017-14508

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several area…

Fix: after 7.7.2.2
Fix from $1,950 2017-09-17
Sugarcrm HIGH 8.8
CVE-2017-14509EPSS 6%

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote fil…

Fix: after 7.7.2.2
Fix from $1,950 2017-09-17
Sugarcrm MEDIUM 6.1
CVE-2017-14510

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLea…

Fix: after 7.7.2.2
Fix from $1,600 2017-09-17
Sugarcrm HIGH 7.8
CVE-2015-5946

Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executab…

No fix yet
Fix from $1,950 2017-08-07
Sugarcrm HIGH 7.5
CVE-2011-4833

Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0b…

No fix yet
Fix from $1,950 2011-12-15
Sugarcrm MEDIUM 5.0
CVE-2011-3803

SugarCRM 6.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…

Mitigation only
Fix from $1,600 2011-09-24
Sugarcrm HIGH 7.5
CVE-2009-2978

SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary …

Fix: after 5.2.0g
Fix from $1,950 2009-08-27
Sugarcrm MEDIUM 6.0
CVE-2009-2146EPSS 21%

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows…

Fix: after 5.2e
Fix from $1,600 2009-06-22
Sugarcrm MEDIUM 5.0
CVE-2008-2045EPSS 5%

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full …

Patch available
Fix from $1,600 2008-05-01
Sugarcrm MEDIUM 6.8
CVE-2006-6712

Cross-site scripting (XSS) vulnerability in SugarCRM Open Source 4.5.0f and earlier allows remote attackers to inject arbitrary web script or HTML vi…

Fix: after 4.5.0f
Fix from $1,600 2006-12-23
Sugar Suite HIGH 7.5
CVE-2006-5082

Unspecified vulnerability in Sugar Suite Open Source (SugarCRM) before 4.2.1 Patch C (20060917) has unspecified impact, related to code execution, an…

Patch available
Fix from $1,950 2006-09-29
Sugarcrm MEDIUM 6.4
CVE-2006-2460EPSS 10%

Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SES…

No fix yet
Fix from $1,600 2006-05-19
Sugar Suite HIGH 7.5
CVE-2005-4087

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlie…

No fix yet
Fix from $1,950 2005-12-08