Description
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP ULike Cross-Site Scripting (3.1)
WordPress Plugin ARI Adminer-WordPress Database Manager Cross-Site Request Forgery (1.1.13)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-43950)
WordPress Plugin qTranslate X Multiple Cross-Site Scripting Vulnerabilities (3.4.6.8)