Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.
Remediation
References
Related Vulnerabilities
MediaWiki Incorrect Default Permissions Vulnerability (CVE-2011-4361)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1611)
WordPress Plugin ByREV WP-PICShield Cross-Site Request Forgery (1.9.7)
OpenSSL Cryptographic Issues Vulnerability (CVE-2009-2409)
PHP Reliance on Cookies without Validation and Integrity Checking Vulnerability (CVE-2020-7070)