Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.
Remediation
References
Related Vulnerabilities
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2020-15842)
WordPress Plugin Store Locator for WordPress with Google Maps-LotsOfLocales SQL Injection (3.11)
Chamilo Improper Privilege Management Vulnerability (CVE-2022-27421)
Microsoft SQL Server CVE-2023-21718 Vulnerability (CVE-2023-21718)