Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-1870 Vulnerability (CVE-2006-1870)
WordPress Plugin Rotating Testimonial Cross-Site Scripting (1.1)
WebLogic Improper Input Validation Vulnerability (CVE-2020-10693)
WordPress 4.6.x Possible SQL Injection Vulnerability (4.6 - 4.6.7)
WordPress Plugin Instagram Plugin-InstaLinker Cross-Site Scripting (1.1.1)