VYPR

SugarCRM Community Edition

by Sugarcrm

CVEs (4)

  • CVE-2018-6308CriJan 25, 2018
    risk 0.64cvss 9.8epss 0.01

    Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Campaigns\utils.php, the default_currency_name parameter to modules\Configurator\controller.php and modules\Currencies\Currency.php,…

  • CVE-2018-17784MedOct 10, 2018
    risk 0.43cvss 6.1epss 0.04

    Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

  • CVE-2009-2146Jun 22, 2009
    risk 0.05cvss epss 0.21

    Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the…

  • CVE-2008-2045May 1, 2008
    risk 0.03cvss epss 0.05

    Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds…