SugarCRM ConnectorsController...

- AV AC AU C I A
发布: 2019-01-01
修订: 2025-04-13

SugarCRM versions prior to 7.9.4.0 and 7.11.0.0 suffer from a server-side request forgery vulnerability. The vulnerability is located within the "ConnectorsController::action_CallRest()" method. User input passed through the "url" request parameter is not properly sanitized before being used in a call to the "file_get_contents" function.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息