CVE-2017-14508
Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sugarcrm/sugarcrm
- Source
- cve@mitre.org
References
- https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities/Exploit, Third Party Advisory
- https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2017-006/Vendor Advisory
- https://www.synology.com/support/security/Synology_SA_17_53_SugarCRM
- https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities/Exploit, Third Party Advisory
- https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2017-006/Vendor Advisory
- https://www.synology.com/support/security/Synology_SA_17_53_SugarCRM
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.