Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
Remediation
References
Related Vulnerabilities
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499)
WordPress Other Vulnerability (CVE-2007-1599)
Drupal Incorrect Authorization Vulnerability (CVE-2017-6377)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-30153)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-2891)