peter bassill · operator
$ cve CVE-2011-4833 JSON

CVE-2011-4833 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.96% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2011-12-15
Last modified2026-06-16

Affected (1)

VendorProduct
sugarcrmsugarcrm

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD