Description SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user. Remediation References CVE-2019-17295 Related Vulnerabilities Sqlite Improper Initialization Vulnerability (CVE-2020-11655) XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35159) WordPress 5.8.x Multiple Vulnerabilities (5.8 - 5.8.5) Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-35611) Apache HTTP Server Other Vulnerability (CVE-2003-0132) Severity High Classification CVE-2019-17295 CWE-138 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities