Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
Remediation
References
Related Vulnerabilities
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5492)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-16854)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.30)
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-16397)