[FD] [KIS-2018-08] SugarCRM (Web Logic Hooks module) Path Traversal Vulnerability

2018-12-31 Thread Egidio Romano
-- SugarCRM (Web Logic Hooks module) Path Traversal Vulnerability -- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.5.0, 8.0.2,

[FD] [KIS-2018-07] SugarCRM (Web Logic Hooks module) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
-- SugarCRM (Web Logic Hooks module) PHP Code Injection Vulnerability -- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.

[FD] [KIS-2018-06] SugarCRM (addLabels) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
- SugarCRM (addLabels) PHP Code Injection Vulnerability - [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0. [-] Vulnerabil

[FD] [KIS-2018-05] SugarCRM (SaveDropDown) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
SugarCRM (SaveDropDown) PHP Code Injection Vulnerability [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.5.0, 8.0.2, and 8.2.0. [-] V

[FD] [KIS-2018-04] SugarCRM (ConnectorsController) Server-Side Request Forgery Vulnerability

2018-12-31 Thread Egidio Romano
- SugarCRM (ConnectorsController) Server-Side Request Forgery Vulnerability - [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All v

[FD] [KIS-2018-03] SugarCRM (portal_get_related_notes) SQL Injection Vulnerability

2018-12-31 Thread Egidio Romano
--- SugarCRM (portal_get_related_notes) SQL Injection Vulnerability --- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.4.0 and 7

[FD] [KIS-2018-02] SugarCRM (WorkFlow module) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
--- SugarCRM (WorkFlow module) PHP Code Injection Vulnerability --- [-] Software Link: http://www.sugarcrm.com [-] Affected Versions: All versions prior to 7.9.4.0 and 7.11.0.0. [

[FD] [KIS-2018-01] Oracle Application Express (AnyChart) Flash-based Cross-Site Scripting Vulnerability

2018-12-31 Thread Egidio Romano
Oracle Application Express (AnyChart) Flash-based Cross-Site Scripting Vulnerability [-] Software Link: https://apex.oracle.c