SugarCRM Web Logic Hooks Module PHP...

- AV AC AU C I A
发布: 2019-01-01
修订: 2025-04-13

SugarCRM versions prior to 7.9.5.0, 8.0.2, and 8.2.0 suffer from a PHP code injection vulnerability. User input passed through the "trigger_event" parameter is not properly sanitized before being used to save PHP code into the 'logic_hooks.php' file through the Web Logic Hooks module. This can be exploited to inject and execute arbitrary PHP code. Successful exploitation of this vulnerability requires admin privileges.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息