Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Secure File Manager Arbitrary File Upload (2.9.3)
WordPress Plugin OMFG Mobile Pro Cross-Site Scripting (1.1.26)
WordPress Plugin Count per Day Information Disclosure (3.2.5)
Oracle JRE CVE-2018-2790 Vulnerability (CVE-2018-2790)
WordPress Plugin Chatbot with IBM Watson Cross-Site Scripting (0.8.20)