PT-2023-25326 · Sugarcrm · Sugarcrm Enterprise

·

CVE-2023-35809

·

Publicado

2023-06-17

·

Atualizado

2024-12-17

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SugarCRM Enterprise versions prior to 11.0.6 SugarCRM Enterprise versions 12.x prior to 12.0.3
Description An issue has been identified in the REST API of SugarCRM, allowing for a Bean Manipulation vulnerability. This vulnerability can be exploited by using a crafted request to inject custom PHP code through the REST API due to missing input validation. The issue can be exploited with regular user privileges.
Recommendations For SugarCRM Enterprise versions prior to 11.0.6, update to version 11.0.6 or later. For SugarCRM Enterprise versions 12.x prior to 12.0.3, update to version 12.0.3 or later.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35809

Produtos afetados

Sugarcrm Enterprise