Description
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.
Remediation
References
Related Vulnerabilities
WordPress Plugin ThemeREX Addons Remote Code Execution (All)
WordPress Plugin WPML (WordPress Multilingual) Multiple Vulnerabilities (3.1.8.6)
Lighttpd Uncontrolled Resource Consumption Vulnerability (CVE-2022-30780)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2484)