Description
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2012-2336)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-2506)
Apache HTTP Server CVE-2009-3720 Vulnerability (CVE-2009-3720)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Information Disclosure (9.7.1)