SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-14509

A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string.

HIGH 8.8EPSS 5.77%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string. Proper input validation has been added to mitigate this issue.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
5.77% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
sugarcrm/sugarcrm
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.