Vulnerabilities > Sugarcrm > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-07 CVE-2019-17319 SQL Injection vulnerability in Sugarcrm
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
network
low complexity
sugarcrm CWE-89
8.8
2019-10-07 CVE-2019-17318 SQL Injection vulnerability in Sugarcrm
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
network
low complexity
sugarcrm CWE-89
8.8
2019-10-07 CVE-2019-17317 Unspecified vulnerability in Sugarcrm
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
network
low complexity
sugarcrm
7.2
2019-10-07 CVE-2019-17316 Unspecified vulnerability in Sugarcrm
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
network
low complexity
sugarcrm
8.8
2019-10-07 CVE-2019-17315 Unspecified vulnerability in Sugarcrm
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
network
low complexity
sugarcrm
7.2
2017-09-17 CVE-2017-14509 Improper Input Validation vulnerability in Sugarcrm
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).
network
low complexity
sugarcrm CWE-20
8.8
2017-09-17 CVE-2017-14508 SQL Injection vulnerability in Sugarcrm
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).
network
low complexity
sugarcrm CWE-89
8.8
2017-08-07 CVE-2015-5946 Incomplete Blacklist vulnerability in Sugarcrm 6.5.22
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
local
low complexity
sugarcrm CWE-184
7.8