CVE-2017-14509: SugarCRM
High severity, CVSS 8.8. EPSS: 5.8% chance of exploitation in the next 30 days.
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string. Proper input validation has been added to mitigate this issue.
Affected products
- SugarCRM SugarCRM: up to and including 7.7.2.2; version 6.5.26 only; version 7.8.0.0 only; version 7.8.0.1 only; version 7.8.1.0 only; version 7.8.2.0 only; …
Published 2017-09-17. Last modified 2026-06-17.