Description SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user. Remediation References CVE-2019-17305 Related Vulnerabilities Oracle JRE CVE-2019-2989 Vulnerability (CVE-2019-2989) WordPress Plugin Qualified Electronic Signatures by eID Easy Supply Chain Attack [Polyfill.io] (3.3.0) MySQL CVE-2021-35648 Vulnerability (CVE-2021-35648) Apache HTTP Server Other Vulnerability (CVE-2000-0868) Sqlite NULL Pointer Dereference Vulnerability (CVE-2020-9327) Severity High Classification CVE-2019-17305 CWE-94 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities