漏洞描述 【漏洞对象】SugarCRM 【涉及版本】SugarCRM <= 6.5.23 PHP5 < 5.6.25 PHP7 < 7.0.10 【漏洞描述】CRM程序对攻击者恶意构造的序列化数据进行了反序列化的处理,从而使攻击者可以在未授权状态下执行任意代码。
相关漏洞推荐 CVE-2018-5715: SugarCRM 3.5.1 - Cross-Site Scripting POC 2025-08-01 | SugarCRM SugarCRM 3.5.1 is vulnerable to cross-site scripting via phprint.php and a parameter name in the que... CVE-2019-14974: SugarCRM Enterprise 9.0.0 - Cross-Site Scripting POC 2025-08-01 | SugarCRM Enterprise SugarCRM Enterprise 9.0.0 contains a cross-site scripting vulnerability via mobile/error-not-support... CVE-2023-22952: SugarCRM Unauthenticated - Remote Code Execution POC 2025-08-01 | SugarCRM In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the Emai... SourceCodester Pet Grooming Management Software SQL注入漏洞 无POC 2025-09-22 00:22:31 | SourceCodester Pet Grooming Management Software SourceCodester Pet Grooming Management Software是SourceCodester开源的一个宠物美容管理系统。 SourceCodester Pet Groo... D-Link DIR-645 命令注入漏洞 无POC 2025-09-22 00:22:31 | D-Link DIR-645 D-Link DIR-645是中国友讯(D-Link)公司的一款无线路由器。 D-Link DIR-645 105B01版本存在命令注入漏洞,该漏洞源于对文件/soap.cgi中参数service的错...