SugarCRM.CE.Unserialize.PHP.Code.Execution

description-logoDescription

This indicates an attempt to exploit a remote Code Execution vulnerability in SugarCRM CE.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. Remote attackers may be able to exploit this to execute arbitrary code on remote systems by including PHP sequences in certain parameters.

affected-products-logoAffected Products

SugarCRM CE 6.3.1 and prior versions

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary code in vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to the latest version available from the website.
http://www.sugarcrm.com/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)