Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Icons with Links Widget Cross-Site Scripting (1.2)
Opencart Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3990)
MongoDb Integer Overflow or Wraparound Vulnerability (CVE-2019-2392)
Oracle Application Server Other Vulnerability (CVE-2006-5353)
WordPress Plugin Product Import Export for WooCommerce Cross-Site Request Forgery (1.7.4)