SugarCRM Community Edition Information Disclosure, SQL Injection and HTML Injection Vulnerabilities
BID:55356
Info
SugarCRM Community Edition Information Disclosure, SQL Injection and HTML Injection Vulnerabilities
| Bugtraq ID: | 55356 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2012 12:00AM |
| Updated: | Aug 30 2012 12:00AM |
| Credit: | Brendan Coles |
| Vulnerable: |
SugarCRM SugarCRM Community Edition 6.5.2 |
| Not Vulnerable: |
SugarCRM SugarCRM Community Edition 6.5.3 |
Discussion
SugarCRM Community Edition Information Disclosure, SQL Injection and HTML Injection Vulnerabilities
SugarCRM Community Edition is prone to multiple information-disclosure vulnerabilities, an SQL-injection vulnerability, and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to harvest sensitive information, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
SugarCRM Community Edition 6.5.2 is vulnerable; other versions may also be affected.
SugarCRM Community Edition is prone to multiple information-disclosure vulnerabilities, an SQL-injection vulnerability, and an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage these issues to harvest sensitive information, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
SugarCRM Community Edition 6.5.2 is vulnerable; other versions may also be affected.
Exploit / POC
References
SugarCRM Community Edition Information Disclosure, SQL Injection and HTML Injection Vulnerabilities
References:
References:
- SugarCRM Community Edition 6.5.2 (Build 8410) multiple vulnerabilities (Brendan Coles)
- SugarCRM Homepage (SugarCRM)