CVE-2020-7472

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/11/2020
Last modified:
21/07/2021

Description

An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:* 8.0.0 (including) 8.0.7 (excluding)
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:professional:*:*:* 8.0.0 (including) 8.0.7 (excluding)
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:ultimate:*:*:* 8.0.0 (including) 8.0.7 (excluding)
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:* 9.0.0 (including) 9.0.4 (excluding)
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:professional:*:*:* 9.0.0 (including) 9.0.4 (excluding)
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:ultimate:*:*:* 9.0.0 (including) 9.0.4 (excluding)