Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.
Remediation
References
Related Vulnerabilities
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-5540)
TYPO3 Improper Input Validation Vulnerability (CVE-2011-4904)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1902)
Dolibarr Missing Authorization Vulnerability (CVE-2018-10092)