Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SugarCRM Documents和Emails模块SQL注入漏洞
Vulnerability Description
SugarCRM是美国SugarCRM公司的一套开源的客户关系管理系统(CRM)。Documents和Emails module都是其中的模块。Documents是一个文档管理模块。Emails是一个电子邮件模块。 SugarCRM中的Documents和Emails模块存在SQL注入漏洞。远程攻击者可通过发送特制的请求利用该漏洞更改SQL数据库。以下版本受到影响:SugarCRM Professional 7.9版本,7.8版本,7.7.2.3之前的版本,Enterprise 7.9版本,7.8版本,7
CVSS Information
N/A
Vulnerability Type
N/A