Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.
Remediation
References
Related Vulnerabilities
ownCloud Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-1850)
Moodle Improper Input Validation Vulnerability (CVE-2017-2576)
WordPress Plugin Portfolio-WordPress Portfolio Cross-Site Scripting (2.8.10)
Drupal Core 8.x.x Cross-Site Request Forgery (8.0.0 - 8.8.12)
IBM WebSEAL Incorrect Authorization Vulnerability (CVE-2023-38368)