Description
An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50982 | An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-09T16:01:32.429Z
Reserved: 2023-10-27T00:00:00.000Z
Link: CVE-2023-46816
Updated: 2024-08-02T20:53:21.825Z
Status : Modified
Published: 2023-10-27T04:15:10.847
Modified: 2024-11-21T08:29:22.003
Link: CVE-2023-46816
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD