Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Campaigns\utils.php, the default_currency_name parameter to modules\Configurator\controller.php and modules\Currencies\Currency.php, the duplicate parameter to modules\Contacts\ShowDuplicates.php, the mergecur parameter to modules\Currencies\index.php and modules\Opportunities\Opportunity.php, and the load_signed_id parameter to modules\Documents\Document.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SugarCRM Community Edition SQL注入漏洞
Vulnerability Description
SugarCRM Community Edition是美国SugarCRM公司的一套开源的客户关系管理系统(CRM)。该系统支持对不同的客户需求进行差异化营销、管理和分配销售线索,实现销售代表的信息共享和追踪。 SugarCRM Community Edition 6.5.26及之前的版本中存在多个SQL注入漏洞。远程攻击者可借助多种方法利用该漏洞执行SQL命令。(包括:向modules\Campaigns\Tracker.php和modules\Campaigns\utils.php文件发送‘track
CVSS Information
N/A
Vulnerability Type
N/A