Description
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Support Plus Responsive Ticket System Privilege Escalation (7.1.4)
WordPress 0.7 Posts SQL Injection Vulnerability (0.7)
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-40572)
WordPress Plugin cdnvote 'cdnvote-post.php' Multiple SQL Injection Vulnerabilities (0.4.1)