Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Plugin:Newsletter 'data' Parameter Information Disclosure (1.5)
PHP Improper Input Validation Vulnerability (CVE-2011-4153)
WordPress Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2020-4050)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2011-2719)