Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2021-38651 Vulnerability (CVE-2021-38651)
WebLogic Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-40690)
IBM RTC Improper Privilege Management Vulnerability (CVE-2021-29774)
WordPress Plugin Users Ultra Membership Cross-Site Scripting (1.5.78)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2017-9788)