SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17306)
Description
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.