#VU21910 Path traversal in SugarCRM - CVE-2019-17312
Published: October 17, 2019
SugarCRM
SugarCRM Inc.
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists in the file function in the REST APIdue to input validation error when processing directory traversal sequences. A remote authenticated attacker can send a specially crafted HTTP request and inject arbitrary PHP code on the target system.