Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server Integer Overflow or Wraparound Vulnerability (CVE-2022-22721)
WordPress Plugin VO Store Locator-WP Store Locator Unspecified Vulnerability (3.2.14)
WordPress Plugin Audio Record Arbitrary File Upload (1.0)
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2024-26267)