An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-50982 An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-09T16:01:32.429Z

Reserved: 2023-10-27T00:00:00

Link: CVE-2023-46816

cve-icon Vulnrichment

Updated: 2024-08-02T20:53:21.825Z

cve-icon NVD

Status : Modified

Published: 2023-10-27T04:15:10.847

Modified: 2024-11-21T08:29:22.003

Link: CVE-2023-46816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.