SugarCRM 6.5.18 fopen() Command Injection / XSS / SSRF

SugarCRM versions 6.5.18 and below suffer from a MySugar::addDashlet insecure fopen() usage that can lead to command injection, cross site scripting, and server-side request forgery exploitation.

Leave a Reply