← Back

CVE-2017-14509

nvd nist
Published: Sep 17, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string. Proper input validation has been added to mitigate this issue.

Affected (10)

Products: Sugarcrm: Sugarcrm
1 product
Sugarcrm
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Sugarcrm
Up to 7.7.2.2
Version 6.5.26
Version 7.8.0.0
Version 7.8.0.1
Version 7.8.1.0
Version 7.8.2.0
Version 7.8.2.1
Version 7.9.0.0
Version 7.9.0.1
Version 7.9.1.0

References (6)

Timeline

No history available yet.