CVE-2019-17314

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.
Configurations

Configuration 1

cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:professional:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:professional:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:professional:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:ultimate:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:ultimate:*:*:*
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:ultimate:*:*:*

Information

Published : 2019-10-07 04:15

Updated : 2019-10-09 04:50


NVD link : CVE-2019-17314

Mitre link : CVE-2019-17314

Products Affected
No products.
CWE