CVE-2024-58258: SugarCRM

High severity, CVSS 7.2. EPSS: 18.5% chance of exploitation in the next 30 days.

SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

Affected products

  • SugarCRM SugarCRM: before 13.0.4 (fixed in 13.0.4); from 14, before 14.0.1 (fixed in 14.0.1)

Published 2025-07-13. Last modified 2026-06-17.