Path traversal in SugarCRM - CVE-2019-17313
Published: October 17, 2019
SugarCRM
Detailed vulnerability description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists in the Studio moduledue to input validation error when processing directory traversal sequences. A remote authenticated developer user can send a specially crafted HTTP request and inject arbitrary PHP code on the target system.