PT-2023-25328 · Docusign+1 · Docusign+1

·

CVE-2023-35810

·

Publicado

2023-06-17

·

Atualizado

2023-08-23

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SugarCRM Enterprise versions prior to 11.0.6 SugarCRM Enterprise versions 12.x prior to 12.0.3
Description A Second-Order PHP Object Injection issue has been identified in the DocuSign module. This occurs due to missing input validation, allowing custom PHP code to be injected and executed through crafted requests. Admin user privileges are required to exploit this issue. Editions other than Enterprise are also affected.
Recommendations For SugarCRM Enterprise versions prior to 11.0.6, update to version 11.0.6 or later. For SugarCRM Enterprise versions 12.x prior to 12.0.3, update to version 12.0.3 or later. As a temporary workaround, consider restricting access to the DocuSign module until a patch is applied.

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35810

Produtos afetados

Docusign
Sugarcrm Enterprise