QID 731025

Date Published: 2023-12-20

QID 731025: SugarCRM Multiple Security Vulnerability

SugarCRM is a customer relationship management system. SugarCRM's functionality includes sales-force automation, marketing campaigns, customer support, collaboration, Mobile CRM, Social CRM and reporting.

Affected Versions:
SugarCRM v13.0.0 prior to 13.0.2
SugarCRM v12.0.0 prior to 12.0.4

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version via sugar_version.json endpoint.

Using a specially crafted request, custom PHP code can be injected through the Notes module because of missing input validation

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to sugarcrm-sa-2023-010sugarcrm-sa-2023-011 to remediate these vulnerabilities.

    CVEs related to QID 731025

    Software Advisories
    Advisory ID Software Component Link
    sugarcrm-sa-2023-010 URL Logo support.sugarcrm.com/resources/security/sugarcrm-sa-2023-010/
    sugarcrm-sa-2023-011 URL Logo support.sugarcrm.com/resources/security/sugarcrm-sa-2023-011