Description
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
Remediation
References
Related Vulnerabilities
Moodle Other Vulnerability (CVE-2006-6625)
MySQL CVE-2019-2739 Vulnerability (CVE-2019-2739)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2203)
WordPress Plugin Jigoshop Multiple Unspecified Vulnerabilities (1.17.13)
WordPress Plugin WPFront Scroll Top Cross-Site Scripting (2.0.6.07225)