Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2503 Vulnerability (CVE-2019-2503)
WordPress Plugin Subscriber by BestWebSoft Cross-Site Scripting (1.3.4)
WordPress Plugin Video Gallery-Vimeo and YouTube Gallery Cross-Site Scripting (1.1.4)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Scripting (1.9.14)