Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.
Remediation
References
Related Vulnerabilities
Drupal Core 9.0.x Security Bypass (9.0.0 - 9.0.5)
Seo Panel Observable Discrepancy Vulnerability (CVE-2024-22647)
Oracle HTTP Server Use After Free Vulnerability (CVE-2019-0211)
WordPress Plugin RoyalSlider Cross-Site Scripting (3.2.4)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4400)