CVE-2011-4833 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 1.96% — more likely to be exploited than 80% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-12-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| sugarcrm | sugarcrm |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SugarCRM Community Edition 6.3.0RC1 - 'index.php' Multiple SQL Injections | 2011-11-30 |
References
- http://secunia.com/advisories/47011
- http://securitytracker.com/id?1026369
- http://www.osvdb.org/77459
- http://www.securityfocus.com/archive/1/520685/100/0/threaded
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47800
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47805
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47806
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47839
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71586
- https://www.htbridge.ch/advisory/sql_injection_in_sugarcrm.html
- http://secunia.com/advisories/47011
- http://securitytracker.com/id?1026369
- http://www.osvdb.org/77459
- http://www.securityfocus.com/archive/1/520685/100/0/threaded
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47800
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47805
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47806
- http://www.sugarcrm.com/crm/support/bugs.html#issue_47839
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71586
- https://www.htbridge.ch/advisory/sql_injection_in_sugarcrm.html
→ the Explorer · watch your stack · NVD