CVE-2011-4833: SugarCRM

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0beta1 allow remote attackers to execute arbitrary SQL commands via the (1) where and (2) order parameters in a get_full_list action to index.php.

Affected products

  • SugarCRM SugarCRM: version 6.1.0 only; version 6.1.1 only; version 6.1.2 only; version 6.1.3 only; version 6.1.4 only; version 6.1.5 only; …

Published 2011-12-15. Last modified 2026-06-16.