Description SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user. Remediation References CVE-2019-17319 Related Vulnerabilities WordPress Plugin Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages Multiple Cross-Site Scripting Vulnerabilities (45.0) Dot CMS Other Vulnerability (CVE-2022-26352) Rukovoditel Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-13590) WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.38) MySQL CVE-2024-20975 Vulnerability (CVE-2024-20975) Severity High Classification CVE-2019-17319 CWE-138 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities