Description SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user. Remediation References CVE-2019-17317 Related Vulnerabilities WordPress Plugin Contact Form DB Cross-Site Scripting (2.8.19) WordPress Plugin Catpro Gallery Arbitrary File Upload (3.8) WordPress Plugin Easy Digital Downloads-Simple eCommerce for Selling Digital Files Cross-Site Scripting (2.10.3) WordPress Plugin Comments-wpDiscuz Cross-Site Scripting (3.1.4) PHP Other Vulnerability (CVE-2002-0081) Severity High Classification CVE-2019-17317 CWE-915 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities