Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
Remediation
References
Related Vulnerabilities
WordPress Plugin WebP Express Arbitrary File Disclosure (0.14.10)
WordPress Plugin WooCommerce Checkout Manager Multiple Unspecified Vulnerabilities (3.6.9)
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4452)
WordPress Credentials Management Errors Vulnerability (CVE-2016-5838)