CVE-2012-0694: SugarCRM

Critical severity, CVSS 9.8. EPSS: 67.3% chance of exploitation in the next 30 days.

SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.

Affected products

  • SugarCRM SugarCRM: up to and including 6.3.1

Published 2019-10-29. Last modified 2026-06-16.