CVE-2019-17312: SugarCRM

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.

Affected products

  • SugarCRM SugarCRM: from 7.9.0.0, before 7.9.5.0 (fixed in 7.9.5.0); from 8.0.0, before 8.0.4 (fixed in 8.0.4); from 9.0.0, before 9.0.2 (fixed in 9.0.2)

Published 2019-10-07. Last modified 2026-06-17.