← Back

CVE-2020-7472

nvd nist
Published: Nov 12, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).

Affected (6)

Products: Sugarcrm: Sugarcrm
1 product
Sugarcrm
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Sugarcrm
From 8.0.0 to 8.0.7
From 9.0.0 to 9.0.4
From 8.0.0 to 8.0.7
From 9.0.0 to 9.0.4
From 8.0.0 to 8.0.7
From 9.0.0 to 9.0.4

References (4)

Timeline

No history available yet.