CVE-2012-0694: SugarCRM
Critical severity, CVSS 9.8. EPSS: 67.3% chance of exploitation in the next 30 days.
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
Affected products
- SugarCRM SugarCRM: up to and including 6.3.1
Published 2019-10-29. Last modified 2026-06-16.