SugarCRM Community Edition RSS Module Information Disclosure Vulnerability
BID:28981
Info
SugarCRM Community Edition RSS Module Information Disclosure Vulnerability
| Bugtraq ID: | 28981 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2045 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Roberto Suggi Liverani Craig |
| Vulnerable: |
SugarCRM SugarCRM Community Edition 5.0 SugarCRM SugarCRM Community Edition 4.5.1 |
| Not Vulnerable: |
SugarCRM SugarCRM Community Edition 5.0.0c SugarCRM SugarCRM Community Edition 4.5.1j |
Discussion
SugarCRM Community Edition RSS Module Information Disclosure Vulnerability
SugarCRM Community Edition is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input. The vulnerability affects the RSS module.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
SugarCRM Community Edition 4.5.1 and 5.0.0 are vulnerable; other versions may also be affected.
SugarCRM Community Edition is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input. The vulnerability affects the RSS module.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
SugarCRM Community Edition 4.5.1 and 5.0.0 are vulnerable; other versions may also be affected.
Exploit / POC
SugarCRM Community Edition RSS Module Information Disclosure Vulnerability
Attackers can exploit this vulnerability via a browser.
Attackers can exploit this vulnerability via a browser.
Solution / Fix
SugarCRM Community Edition RSS Module Information Disclosure Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
SugarCRM Community Edition RSS Module Information Disclosure Vulnerability
References:
References:
- Fixed Bugs in 4.5.1j (SugarCRM)
- Sugar Community Edition 4.5.1 Patch J (SugarCRM)
- Sugar Community Edition 5.0.0 Patch C (SugarCRM)
- SugarCRM Homepage (SugarCRM)
- SugarCRM Community Edition Local File Disclosure Vulnerability ([email protected])