SugarCRM Unspecified SQL Injection Vulnerability
BID:36118
Info
SugarCRM Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 36118 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2009 12:00AM |
| Updated: | Aug 24 2009 10:23PM |
| Credit: | Takeshi Terada of Mitsui Bussan Secure Directions, Inc. |
| Vulnerable: |
SugarCRM SugarCRM Community Edition 5.0 SugarCRM SugarCRM Community Edition 4.5.1 SugarCRM SugarCRM Community Edition 5.0.0c SugarCRM SugarCRM Community Edition 4.5.1j SugarCRM SugarCRM 5.2 g SugarCRM SugarCRM 5.2 e SugarCRM SugarCRM 5.0 k SugarCRM SugarCRM 4.5.1 o SugarCRM SugarCRM 1.0 SugarCRM Sugar Open Source 4.5.0 g SugarCRM Sugar Open Source 4.5.0 f |
| Not Vulnerable: |
SugarCRM SugarCRM 5.2 h SugarCRM SugarCRM 5.0 l SugarCRM SugarCRM 4.5.1 p |
Discussion
SugarCRM Unspecified SQL Injection Vulnerability
SugarCRM is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to SugarCRM 5.2.0h, 5.0.0l, and 4.5.1p are vulnerable.
SugarCRM is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to SugarCRM 5.2.0h, 5.0.0l, and 4.5.1p are vulnerable.
Exploit / POC
SugarCRM Unspecified SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
SugarCRM Unspecified SQL Injection Vulnerability
Solution:
The vendor has released updates. Please see the references for details.
Solution:
The vendor has released updates. Please see the references for details.
References
SugarCRM Unspecified SQL Injection Vulnerability
References:
References:
- Sugar Community Edition 5.0.0l and 4.5.1p Now Available (SugarCMS)
- Sugar Community Edition 5.2.0 Patch H (SugarCMS)
- SugarCRM Homepage (SugarCRM)