sugarcrm kayıtları
sugarcrm üreticisine ait 68 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,5
- Silahlaştırılmış
- 2 · %2,9
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 22 gün
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')15
- CWE-94 Improper Control of Generation of Code ('Code Injection')14
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-20 Improper Input Validation5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
68 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
89Hemen | CVE-2023-22952Silahlaştırılmış | In SugarCRM before 12.0.sugarcrm · sugarcrm · CWE-20 | Yüksek8,8 | KEV | %80,1 | 11 Oca 2023 |
59Planlayın | CVE-2012-0694Silahlaştırılmış | SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrarysugarcrm · sugarcrm · CWE-20 | Kritik9,8 | — | %67,3 | 29 Eki 2019 |
41Planlayın | CVE-2014-3244İstismar yok | XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files sugarcrm · sugarcrm · CWE-611 | Kritik9,8 | — | %5,0 | 1 Şub 2018 |
41Planlayın | CVE-2004-1227Kavram kanıtı | Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly exsugarcrm · sugar sales | Kritik10,0 | — | %4,2 | 10 Oca 2005 |
41Planlayın | CVE-2004-1225Kavram kanıtı | SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privilesugarcrm · sugarcrm | Kritik10,0 | — | %1,8 | 10 Oca 2005 |
40Planlayın | CVE-2020-7472İstismar yok | An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0sugarcrm · sugarcrm · CWE-20 | Kritik9,8 | — | %3,2 | 12 Kas 2020 |
39İzleyin | CVE-2018-6308İstismar yok | Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and mosugarcrm · sugarcrm · CWE-89 | Kritik9,8 | — | %1,1 | 25 Oca 2018 |
37İzleyin | CVE-2017-14509İstismar yok | An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).sugarcrm · sugarcrm · CWE-20 | Yüksek8,8 | — | %5,8 | 17 Eyl 2017 |
36İzleyin | CVE-2017-14508İstismar yok | An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).sugarcrm · sugarcrm · CWE-89 | Yüksek8,8 | — | %2,6 | 17 Eyl 2017 |
36İzleyin | CVE-2019-17311İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.sugarcrm · sugarcrm · CWE-22 | Yüksek8,8 | — | %2,0 | 7 Eki 2019 |
36İzleyin | CVE-2019-17312İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.sugarcrm · sugarcrm · CWE-22 | Yüksek8,8 | — | %2,0 | 7 Eki 2019 |
36İzleyin | CVE-2019-17313İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.sugarcrm · sugarcrm · CWE-22 | Yüksek8,8 | — | %2,0 | 7 Eki 2019 |
35İzleyin | CVE-2019-17316İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.sugarcrm · sugarcrm · CWE-1321 | Yüksek8,8 | — | %1,5 | 7 Eki 2019 |
35İzleyin | CVE-2019-17303İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.sugarcrm · sugarcrm · CWE-94 | Yüksek8,8 | — | %1,4 | 7 Eki 2019 |
35İzleyin | CVE-2019-17308İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.sugarcrm · sugarcrm · CWE-94 | Yüksek8,8 | — | %1,4 | 7 Eki 2019 |
35İzleyin | CVE-2019-17305İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.sugarcrm · sugarcrm · CWE-94 | Yüksek8,8 | — | %1,4 | 7 Eki 2019 |
35İzleyin | CVE-2019-17300İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.sugarcrm · sugarcrm · CWE-94 | Yüksek8,8 | — | %1,4 | 7 Eki 2019 |
35İzleyin | CVE-2019-17302İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.sugarcrm · sugarcrm · CWE-94 | Yüksek8,8 | — | %1,4 | 7 Eki 2019 |
35İzleyin | CVE-2023-35809İstismar yok | An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3.sugarcrm · sugarcrm · CWE-94 | Yüksek8,8 | — | %1,3 | 17 Haz 2023 |
35İzleyin | CVE-2023-35808İstismar yok | An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3.sugarcrm · sugarcrm · CWE-434 | Yüksek8,8 | — | %1,3 | 17 Haz 2023 |
35İzleyin | CVE-2019-17319İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.sugarcrm · sugarcrm · CWE-89 | Yüksek8,8 | — | %1,2 | 7 Eki 2019 |
35İzleyin | CVE-2019-17318İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.sugarcrm · sugarcrm · CWE-89 | Yüksek8,8 | — | %1,2 | 7 Eki 2019 |
35İzleyin | CVE-2019-17295İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.sugarcrm · sugarcrm · CWE-89 | Yüksek8,8 | — | %1,2 | 7 Eki 2019 |
35İzleyin | CVE-2019-17298İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.sugarcrm · sugarcrm · CWE-89 | Yüksek8,8 | — | %1,2 | 7 Eki 2019 |
35İzleyin | CVE-2019-17293İstismar yok | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.sugarcrm · sugarcrm · CWE-89 | Yüksek8,8 | — | %1,2 | 7 Eki 2019 |
- CVE-2023-2295289Hemen
In SugarCRM before 12.0.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %80sugarcrm · sugarcrm11 Oca 2023
- CVE-2012-069459Planlayın
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary
KritikCVSS 9,8SilahlaştırılmışEPSS %67sugarcrm · sugarcrm29 Eki 2019
- CVE-2014-324441Planlayın
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files
KritikCVSS 9,8İstismar yokEPSS %5sugarcrm · sugarcrm1 Şub 2018
- CVE-2004-122741Planlayın
Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly ex
KritikCVSS 10,0Kavram kanıtıEPSS %4sugarcrm · sugar sales10 Oca 2005
- CVE-2004-122541Planlayın
SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privile
KritikCVSS 10,0Kavram kanıtıEPSS %2sugarcrm · sugarcrm10 Oca 2005
- CVE-2020-747240Planlayın
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0
KritikCVSS 9,8İstismar yokEPSS %3sugarcrm · sugarcrm12 Kas 2020
- CVE-2018-630839İzleyin
Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and mo
KritikCVSS 9,8İstismar yokEPSS %1sugarcrm · sugarcrm25 Oca 2018
- CVE-2017-1450937İzleyin
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).
YüksekCVSS 8,8İstismar yokEPSS %6sugarcrm · sugarcrm17 Eyl 2017
- CVE-2017-1450836İzleyin
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).
YüksekCVSS 8,8İstismar yokEPSS %3sugarcrm · sugarcrm17 Eyl 2017
- CVE-2019-1731136İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %2sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1731236İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %2sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1731336İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.
YüksekCVSS 8,8İstismar yokEPSS %2sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1731635İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1730335İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1730835İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1730535İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1730035İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1730235İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2023-3580935İzleyin
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm17 Haz 2023
- CVE-2023-3580835İzleyin
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm17 Haz 2023
- CVE-2019-1731935İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1731835İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1729535İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1729835İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019
- CVE-2019-1729335İzleyin
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.
YüksekCVSS 8,8İstismar yokEPSS %1sugarcrm · sugarcrm7 Eki 2019