CyberSec.Space Logo
Back to CVE Browser

CVE-2023-46815

HIGH
8.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2023-10-27
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using a crafted request, custom PHP code can be injected via the Notes module because of missing input validation. An attacker with regular user privileges can exploit this.

Affected Platforms (CPE)

📦
Sugarcrm

Sugarcrm

>= 12.0.0 and < 12.0.4= 13.0.0= 13.0.1

References & Advisories

Related Vulnerabilities