QID 730704
Date Published: 2023-01-20
QID 730704: SugarCRM Remote Code Execution (RCE) Vulnerability
SugarCRM is a customer relationship management system. SugarCRM's functionality includes sales-force automation, marketing campaigns, customer support, collaboration, Mobile CRM, Social CRM and reporting.
Affected Versions:
SugarCRM v11.0.0 prior to 11.0.5
SugarCRM v12.0.0 prior to 12.0.2
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version via sugar_version.json endpoint.
Note: the detection os marked as practice since only some of the editions of SugarCRM are vulnerable.
Using a specially crafted request, custom PHP code can be injected through the EmailTemplates by the attacker.
Solution
Customers are advised to upgrade to SugarCRM v11.0.5, v12.0.2 to remediate these vulnerabilities.
Vendor References
- sugarcrm-sa-2023-001 -
support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001
CVEs related to QID 730704
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| sugarcrm-sa-2023-001 |
|