Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Hana Flv Player Cross-Site Scripting (3.1.3)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1432)
WordPress Plugin link-list-manager Cross-Site Scripting (1.0)
WordPress Plugin Cool Timeline (Horizontal & Vertical Timeline) Cross-Site Request Forgery (2.0.2)