CVE-2019-17314

EUVD-2019-7727
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
𝑥
= Vulnerable software versions