İçeriğe atla
Noroxi

sugarcrm kayıtları

sugarcrm üreticisine ait 68 yayımlanmış kayıt.

Tüm kayıtlar

68 kayıt
  • In SugarCRM before 12.0.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %80

    sugarcrm · sugarcrm11 Oca 2023

  • CVE-2012-0694
    59Planlayın

    SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary

    KritikCVSS 9,8SilahlaştırılmışEPSS %67

    sugarcrm · sugarcrm29 Eki 2019

  • CVE-2014-3244
    41Planlayın

    XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files

    KritikCVSS 9,8İstismar yokEPSS %5

    sugarcrm · sugarcrm1 Şub 2018

  • CVE-2004-1227
    41Planlayın

    Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly ex

    KritikCVSS 10,0Kavram kanıtıEPSS %4

    sugarcrm · sugar sales10 Oca 2005

  • CVE-2004-1225
    41Planlayın

    SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privile

    KritikCVSS 10,0Kavram kanıtıEPSS %2

    sugarcrm · sugarcrm10 Oca 2005

  • CVE-2020-7472
    40Planlayın

    An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0

    KritikCVSS 9,8İstismar yokEPSS %3

    sugarcrm · sugarcrm12 Kas 2020

  • CVE-2018-6308
    39İzleyin

    Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and mo

    KritikCVSS 9,8İstismar yokEPSS %1

    sugarcrm · sugarcrm25 Oca 2018

  • CVE-2017-14509
    37İzleyin

    An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).

    YüksekCVSS 8,8İstismar yokEPSS %6

    sugarcrm · sugarcrm17 Eyl 2017

  • CVE-2017-14508
    36İzleyin

    An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).

    YüksekCVSS 8,8İstismar yokEPSS %3

    sugarcrm · sugarcrm17 Eyl 2017

  • CVE-2019-17311
    36İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %2

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17312
    36İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %2

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17313
    36İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.

    YüksekCVSS 8,8İstismar yokEPSS %2

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17316
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17303
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17308
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17305
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17300
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17302
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2023-35809
    35İzleyin

    An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm17 Haz 2023

  • CVE-2023-35808
    35İzleyin

    An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm17 Haz 2023

  • CVE-2019-17319
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17318
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17295
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17298
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019

  • CVE-2019-17293
    35İzleyin

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.

    YüksekCVSS 8,8İstismar yokEPSS %1

    sugarcrm · sugarcrm7 Eki 2019