SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF...
High severity
Unreviewed
Published
Jul 14, 2025
to the GitHub Advisory Database
•
Updated Jul 14, 2025
Description
Published by the National Vulnerability Database
Jul 13, 2025
Published to the GitHub Advisory Database
Jul 14, 2025
Last updated
Jul 14, 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
References