CVE-2017-14508
Summary
| CVE | CVE-2017-14508 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-17 21:29:00 UTC |
| Updated | 2017-12-30 02:29:00 UTC |
| Description | An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sugarcrm | Sugarcrm | 6.5.26 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.0.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.0.1 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.1.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.2.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.2.1 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.9.0.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.9.0.1 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.9.1.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 6.5.26 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.0.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.0.1 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.1.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.2.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.8.2.1 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.9.0.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.9.0.1 | All | All | All |
| Application | Sugarcrm | Sugarcrm | 7.9.1.0 | All | All | All |
| Application | Sugarcrm | Sugarcrm | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sugarcrm-sa-2017-006 - SugarCRM Support Site | MISC | support.sugarcrm.com | Vendor Advisory |
| Synology-SA-17:53 SugarCRM | Synology Inc. | CONFIRM | www.synology.com | |
| SugarCRM's Security Diet - Multiple Vulnerabilities | MISC | blog.ripstech.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.