Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Author Image Information Disclosure (1.5)
WordPress Plugin Super Forms-Drag & Drop Form Builder Arbitrary File Upload (4.9.700)
WordPress Plugin WordPress Social Login Cross-Site Scripting (2.0.3)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-0195)