High severity7.2NVD Advisory· Published Oct 7, 2019· Updated Jun 17, 2026
CVE-2019-17314
CVE-2019-17314
Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.
Affected products
6cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:*+ 3 more
- cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:*range: >=7.9.0.0,<7.9.5.0
- cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:professional:*:*:*range: >=7.9.0.0,<7.9.5.0
- cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:ultimate:*:*:*range: >=7.9.0.0,<7.9.5.0
- (no CPE)range: <8.0.4, <9.0.2
- SugarCRM/SugarCRMdescription
- Range: <8.0.4, <9.0.2
Patches
Vulnerability mechanics
References
1- support.sugarcrm.com/Resources/Security/sugarcrm-sa-2019-041/nvdVendor Advisory
News mentions
0No linked articles in our index yet.