Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
Remediation
References
Related Vulnerabilities
WordPress Improper Input Validation Vulnerability (CVE-2008-5695)
Undertow CVE-2022-4492 Vulnerability (CVE-2022-4492)
WordPress Plugin Zielke Specialized Catalog Arbitrary File Upload (3.0.7)
WordPress Plugin bbPress Move Topics PHP Object Injection (1.1.4)
WordPress Plugin Really Simple Gallery Cross-Site Scripting (1.4)