Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Thrive Dashboard Security Bypass (2.3.9.2)
WordPress Plugin Esponce QR Code Generator Cross-Site Scripting (1.4)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.11)
WordPress Plugin lasTunes Cross-Site Scripting (3.6.1)
WordPress Plugin BackupBuddy Arbitrary File Download (8.7.4.1)