CVE-2019-17317

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
sugarcrmsugarcrm
7.9.0.0 ≤
𝑥
< 7.9.5.0
sugarcrmsugarcrm
8.0.0 ≤
𝑥
< 8.0.4
sugarcrmsugarcrm
9.0.0 ≤
𝑥
< 9.0.2
𝑥
= Vulnerable software versions