VYPR
High severity8.8NVD Advisory· Published Oct 7, 2019· Updated Jun 17, 2026

CVE-2019-17312

CVE-2019-17312

Description

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.

Affected products

5
  • Sugarcrm/Sugarcrm4 versions
    cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:*+ 3 more
    • cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:*range: >=7.9.0.0,<7.9.5.0
    • cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:professional:*:*:*range: >=7.9.0.0,<7.9.5.0
    • cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:ultimate:*:*:*range: >=7.9.0.0,<7.9.5.0
    • (no CPE)range: <8.0.4, <9.0.2
  • SugarCRM/SugarCRMdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.