CVE-2017-14509
A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string. Proper input validation has been added to mitigate this issue.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.77% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- sugarcrm/sugarcrm
- Source
- cve@mitre.org
References
- https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities/Exploit, Third Party Advisory
- https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2017-007/Vendor Advisory
- https://www.synology.com/support/security/Synology_SA_17_53_SugarCRM
- https://blog.ripstech.com/2017/sugarcrm-security-diet-multiple-vulnerabilities/Exploit, Third Party Advisory
- https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2017-007/Vendor Advisory
- https://www.synology.com/support/security/Synology_SA_17_53_SugarCRM
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.