VYPR

Configurator

by Sugarcrm

CVEs (2)

  • CVE-2019-17314HigOct 7, 2019
    risk 0.47cvss 7.2epss 0.02

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.

  • CVE-2019-17306HigOct 7, 2019
    risk 0.47cvss 7.2epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.