Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Falang multilanguage for WordPress Cross-Site Scripting (1.3.17)
WordPress Plugin Link Library SQL Injection (5.9.13.26)
MySQL Other Vulnerability (CVE-2010-3681)
WordPress Plugin Quiz Tool Lite Multiple Cross-Site Scripting Vulnerabilities (2.3.15)
WordPress Plugin WPGlobus-Multilingual Everything! Multiple Vulnerabilities (1.9.6)