CVE-2019-17315

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
𝑥
= Vulnerable software versions