Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP PHP widget Information Disclosure (1.0.2)
WordPress Plugin AMP Toolbox Cross-Site Scripting (1.9.4)
MySQL CVE-2018-2775 Vulnerability (CVE-2018-2775)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13663)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-5447)