Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user.
Remediation
References
Related Vulnerabilities
Serendipity Other Vulnerability (CVE-2005-1134)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-8286)
MediaWiki Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2021-42040)
Oracle Database Server CVE-2010-0854 Vulnerability (CVE-2010-0854)