Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-2896 Vulnerability (CVE-2020-2896)
WordPress Plugin Gallery PhotoBlocks Cross-Site Scripting (1.1.42)
IBM RTC Cross-site Scripting (XSS) Vulnerability (CVE-2020-4691)
Next.js CVE-2023-46298 Vulnerability (CVE-2023-46298)
WordPress Plugin Admin Custom Login Cross-Site Request Forgery (3.2.7)