CVE-2023-35809
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jun 17, 2023
Updated: Dec 17, 2024
CWE ID 94
Summary
CVE-2023-35809 is a vulnerability affecting SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. This issue involves a Bean Manipulation flaw in the REST API, which allows for custom PHP code injection due to insufficient input validation. An attacker can exploit this vulnerability with regular user privileges, posing a significant threat. Additionally, editions other than Enterprise are also susceptible to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- SugarCRM
Affected Vendors
- SugarCRM